MITRE ATT&CK Enterprise
T1583.006
enhancement

Web Services

Parent: T1583

Description

Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for adversaries to register for a web-based service that can be abused during later stages of the adversary lifecycle, such as during Command and Control ([Web Service](https://attack.mitre.org/techniques/T1102)), [Exfiltration Over Web Service](https://attack.mitre.org/techniques/T1567), or [Phishing](https://attack.mitre.org/techniques/T1566). Using common services, such as those offered by Google, GitHub, or Twitter, makes it easier for adversaries to hide in expected noise.(Citation: FireEye APT29)(Citation: Hacker News GitHub Abuse 2024) By utilizing a web service, adversaries can make it difficult to physically tie back operations to them.

Mapped SPARTA techniques

1 techniques

  • AWS Ground Station and similar SaaS-style ground-segment offerings register as web services; T1583.006 'Web Services' covers this specific procurement model, downgraded because not all commercial ground-station services are web-services-shaped (some are traditional contracts).

Cite as SafeMode Space, mitre-attack-enterprise T1583.006.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.