216.73.217.22

T1583.006: T1583.006

View on MITRE ATT&CK The MITRE Corporation · Published 16/12/2025 19:38 · Modified 15/04/2026 19:28

Essential information

MITRE technique ID
T1583.006
Confidence
100/100
Revoked
No
Published
16/12/2025 19:38
Modified
15/04/2026 19:28
Author / Source
The MITRE Corporation

Aliases

Web Services

Platforms

PRE

Description

Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for adversaries to register for a web-based service that can be abused during later stages of the adversary lifecycle, such as during Command and Control ([Web Service](https://attack.mitre.org/techniques/T1102)), [Exfiltration Over Web Service](https://attack.mitre.org/techniques/T1567), or [Phishing](https://attack.mitre.org/techniques/T1566). Using common services, such as those offered by Google, GitHub, or Twitter, makes it easier for adversaries to hide in expected noise.(Citation: FireEye APT29)(Citation: Hacker News GitHub Abuse 2024) By utilizing a web service, adversaries can make it difficult to physically tie back operations to them.

Kill chain phases

Kill chainPhase
mitre-attack resource-development

Marking (TLP)

TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references