Acquire Infrastructure: Web Services T1583.006

Tactic: Resource Development

Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for adversaries to register for a web-based service that can be abused during later stages of the adversary lifecycle, such as during Command and Control (Web Service), Exfiltration Over Web Service, or Phishing. Using common services, such as those offered by Google, GitHub, or Twitter, makes it easier for adversaries to hide in expected noise. By utilizing a web service, adversaries can make it difficult to physically tie back operations to them.

Authoring guide

These 2 rules share fields, values, and exclusions.

Fields filtered most (4 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType2eq 2intrusionevent, repo.create
TriggerCount1eq 11
event.dataset1eq 1github.audit
sourcetype1eq 1cisco:sfw:estreamer

Top indicator values (5 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypeeq
intrusionevent
118
EventTypeeq
repo.create
1
TriggerCounteq
1
1
event.dataseteq
github.audit
114
sourcetypeeq
cisco:sfw:estreamer
132

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Elastic 1 rule

Splunk 1 rule