// MITRE ATT&CK
T1584.006 · Web Services
Sub-technique of T1584 · Compromise Infrastructure.
Adversaries may compromise access to third-party web services that can be used during targeting. A variety of popular websites exist for legitimate users to register for web-based services, such as GitHub, Twitter, Dropbox, Google, SendGrid, etc. Adversaries may try to take ownership of a legitimat...
How to detect & mitigate it
Detecting Web Services starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Related techniques
T1583
Acquire Infrastructure T1583.007
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1588.004
Digital Certificates T1583.002
DNS Server T1587.003
Digital Certificates
Acquire Infrastructure T1583.007
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1588.004
Digital Certificates T1583.002
DNS Server T1587.003
Digital Certificates
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.