Cross-source coverage

T1189 / ATT&CK

Drive-by Compromise

3063 rules · 2927 families across 8 sources.

Showing deprecated and atomic-IOC rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:

  • A legitimate website is compromised, allowing adversaries to inject malicious code
  • Script files served to a legitimate website from a publicly writeable cloud storage bucket are modified by an adversary
  • Malicious ads are paid for and served through legitimate ad providers (i.e., Malvertising)
  • Built-in web application interfaces that allow user-controllable content are leveraged for the insertion of malicious scripts or iFrames (e.g., cross-site scripting)

Browser push notifications may also be abused by adversaries and leveraged for malicious code injection via User Execution. By clicking "allow" on browser push notifications, users may be granting a website permission to run JavaScript code on their browser.

Often the website used by an adversary is one visited by a specific community, such as government, a particular industry, or a particular region, where the goal is to compromise a specific user or set of users based on a shared interest. This kind of targeted campaign is often referred to a strategic web compromise or watering hole attack. There are several known examples of this occurring.

Typical drive-by compromise process:

  1. A user visits a website that is used to host the adversary controlled content.
  2. Scripts automatically execute, typically searching versions of the browser and plugins for a potentially vulnerable version. The user may be required to assist in this process by enabling scripting, notifications, or active website components and ignoring warning dialog boxes.
  3. Upon finding a vulnerable version, exploit code is delivered to the browser.
  4. If exploitation is successful, the adversary will gain code execution on the user's system unless other protections are in place. In some cases, a second visit to the website after the initial scan is required before exploit code is delivered.

Unlike Exploit Public-Facing Application, the focus of this technique is to exploit software on a client endpoint upon visiting a website. This will commonly give an adversary access to systems on the internal network instead of external systems that may be in a DMZ.

Tactics
Initial Access
Platforms
Identity Provider · Linux · macOS · Windows
Telemetry
WinEventLog:SecurityWinEventLog:SysmonWinEventLog:Applicationetw:Microsoft-Windows-Kernel-ProcessNSM:Flowauditd:SYSCALLlinux:sysloglinux:SysmonNSM:Connectionsmacos:unifiedlogazure:signinlogsm365:unifiedsaas:authAWS:CloudTrail

How MITRE says to detect it DET0176

Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189)

Windows Analytic 0498

Correlated evidence of anomalous browser/network behavior (suspicious external resource fetches and script injection patterns) followed by atypical child processes, ephemeral execution contexts, memory modification or process injection, and unexpected file drops. Defender sees network requests to previously unseen/suspicious domains or resources + browser process spawning unusual children or loading unsigned modules + file writes or registry changes shortly after those requests.

  • WinEventLog:Security EventCode=4624, 4648
  • WinEventLog:Security EventCode=4688
  • WinEventLog:Sysmon EventCode=3, 22
  • WinEventLog:Application Browser or plugin/application logs showing script errors, plugin enumerations, or unusual extension load events
  • etw:Microsoft-Windows-Kernel-Process Memory Modification / Unmapped module load or suspicious RWX allocations in the process space of a browser process
  • WinEventLog:Sysmon EventCode=11
  • NSM:Flow http.request: HTTP requests and responses for specific script resources, unexpected content-types (application/octet-stream for script URLs), suspicious referrers, or obfuscated javascript resources

Linux Analytic 0499

Correlated evidence of browser or webview fetches to uncommon domains or mutated JS resources (proxy/NGFW logs + Zeek/HTTP logs) followed by unexpected interpreters or script engines executing (python, ruby, sh) spawned from browser processes or user sessions, rapid on-disk staging in /tmp, and outbound connections that deviate from baseline. Defender sees: uncommon resource fetch → short-lived child process executions from user browser context → file writes in temp directories → anomalous outbound C2-like connections.

  • auditd:SYSCALL execve: execve calls where a browser/webview process is parent and child is interpreter (python, sh, ruby) or downloader (curl, wget)
  • linux:syslog Application or browser logs (webview errors, plugin enumerations) indicating suspicious script evaluation or plugin loads
  • NSM:Flow http::response: HTTP responses with suspicious content-type for scripts, long obfuscated javascript bodies, or redirects to exploit kit domains
  • linux:Sysmon New files in /tmp, /var/tmp, $HOME/.cache, executed within TimeWindow after browser HTTP fetch
  • NSM:Connections Outbound connections from newly spawned child processes or from the browser to uncommon endpoints or on anomalous ports

macOS Analytic 0500

Correlated evidence where Safari/Chrome/WebKit-based processes issue network requests for uncommon or obfuscated JS resources followed by spawning of script interpreters, launchd or ad-hoc binaries, unusual child processes, or dynamic library loads into browser processes. Defender sees: proxy/HTTP logs with suspicious resource content + unifiedlogs/ASL showing browser/plugin crashes or extension loads + process events indicating child process creation and file writes to /var/folders or /tmp shortly after the fetch.

  • macos:unifiedlog Logs from unifiedlogging that show browser crashes, plugin enumerations, extension installs or errors around the same time as suspicious network fetches
  • macos:unifiedlog process_create: Process creation where parent is Safari/Google Chrome and child is script interpreter or signed-but-unusual helper binary
  • macos:unifiedlog New files written to /var/folders, /tmp, ~/Library/Caches, or ~/Downloads by browser context or its children
  • NSM:Flow HTTP/HTTPS requests for script resources flagged by content inspection (excessive obfuscation, eval usage, unusual redirects)
  • macos:unifiedlog Anomalous dyld dynamic library loads or RWX memory mappings in browser process

Identity Provider Analytic 0501

Post-compromise identity & session anomalies that follow a drive-by compromise: token reuse from new/unfamiliar IPs, anomalous sign-in patterns for previously inactive users, unexpected consent/grant events, or provisioning changes. Defender sees an endpoint/browser compromise (network + endpoint signals) followed by unusual IdP events: new refresh token issuance, consent/consent-grant events, odd MFA bypass patterns, or unusual OAuth client registrations.

  • azure:signinlogs SignIn: Sign-ins flagged as atypical (new geographic region, unfamiliar device id) shortly after correlated endpoint/browser compromise times
  • m365:unified Application Consent grants, new OAuth client registrations, or unusual admin-level activities executed by a user account shortly after suspected drive-by compromise
  • saas:auth Refresh token issuance or refresh token usage from new IPs or user agents
  • AWS:CloudTrail ConsoleLogin: If IdP backed by cloud provider, Console login from new IP/agent after correlated endpoint compromise

Emerging Threats Open

3039 rules · 2903 families
Detection Severity Format
ET EXPLOIT_KIT ErrTraffic Domain in DNS Lookup (check .first-node .rocks) Critical Suricata
ET EXPLOIT_KIT Malicious TA2726 TDS Domain in DNS Lookup (fetchapiutility .com) Critical Suricata
ET EXPLOIT_KIT Malicious TA2726 TDS Domain in DNS Lookup (packedbrick .com) Critical Suricata
ET EXPLOIT_KIT Malicious TA2726 TDS Domain in TLS SNI (fetchapiutility .com) Critical Suricata
ET EXPLOIT_KIT TA569 Keitaro TDS Domain in DNS Lookup (angularapiworld .com) Critical Suricata
ET EXPLOIT_KIT TA569 Keitaro TDS Domain in DNS Lookup (jqueryapihelpers .com) Critical Suricata
ET EXPLOIT_KIT TA569 Keitaro TDS Domain in DNS Lookup (jqueryapishelpers .com) Critical Suricata
ET EXPLOIT_KIT TA569 Keitaro TDS Domain in TLS SNI (angularapiworld .com) Critical Suricata
ET EXPLOIT_KIT TA569 Keitaro TDS Domain in TLS SNI (jqueryapihelpers .com) Critical Suricata
ET EXPLOIT_KIT TA569 Keitaro TDS Domain in TLS SNI (jqueryapishelpers .com) Critical Suricata

+ 3029 more from Emerging Threats Open → showing the 10 highest-severity

elastic/detection-rules

6 rules
Detection Severity Format
Potential Fake CAPTCHA Phishing Attack High Elastic TOML
Suspicious Browser Child Process High Elastic TOML
WPS Office Exploitation via DLL Hijack High Elastic TOML
Potential Cross Site Scripting (XSS) Low Elastic TOML
Potential Masquerading as Business App Installer Low Elastic TOML
Unusual Web Request Low Elastic TOML

elastic/protections-artifacts

6 rules
Detection Severity Format
Potential Browser Exploit via Fake RPC Messages Undefined Elastic TOML
Potential Execution via Foxmail Exploitation Undefined Elastic TOML
Potential Shellcode Injection by a Browser Process Undefined Elastic TOML
Suspicious Execution via Microsoft OfficeCmd URL Handler Undefined Elastic TOML
Suspicious VirtualProtect via Jscript9 from Internet Explorer Undefined Elastic TOML
WPS Office Exploit via DLL Hijack Undefined Elastic TOML

Azure/Azure-Sentinel

4 rules
Detection Severity Format
Application Gateway WAF - XSS Detection High KQL
A client made a web request to a potentially harmful file (ASIM Web Session schema) Medium KQL
Malformed user agent Medium KQL
Potential IIS code injection attempt Undefined KQL

SigmaHQ/sigma

3 rules
Detection Severity Format
Cross Site Scripting Strings High Sigma
Flash Player Update from Suspicious Location High Sigma
Suspicious Browser Child Process - MacOS Medium Sigma

chronicle/detection-rules

2 rules
Detection Severity Format
underminer_exploit_kit_delivers_malware Undefined YARA-L
wastedlocker_ransomware_hunting_initial_access_and_compromise Undefined YARA-L

splunk/security_content

2 rules
Detection Severity Format
Detect hosts connecting to dynamic domain providers Undefined SPL
Splunk XSS Privilege Escalation via Custom Urls in Dashboard Undefined SPL

socfortress/Wazuh-Rules

1 rule
Detection Severity Format
operation. · office_365.Operation = MessageCreatedHasLink Low Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.