1200KM / detection
T1189 Drive-by Compromise — Detection Rules
Detection workspace for T1189 Drive-by Compromise: 3 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Suspicious Browser Child Process - MacOS · test · medium · {"category":"process_creation","product":"macos"}
- Flash Player Update from Suspicious Location · test · high · {"category":"proxy"}
- Cross Site Scripting Strings · test · high · {"category":"webserver"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0176 Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189)
AN0498 Analytic 0498
Correlated evidence of anomalous browser/network behavior (suspicious external resource fetches and script injection patterns) followed by atypical child processes, ephemeral execution contexts, memory modification or process injection, and unexpected file drops. Defender sees network requests to previously unseen/suspicious domains or resources + browser process spawning unusual children or loading unsigned modules + file writes or registry changes shortly after those requests.
AN0499 Analytic 0499
Correlated evidence of browser or webview fetches to uncommon domains or mutated JS resources (proxy/NGFW logs + Zeek/HTTP logs) followed by unexpected interpreters or script engines executing (python, ruby, sh) spawned from browser processes or user sessions, rapid on-disk staging in /tmp, and outbound connections that deviate from baseline. Defender sees: uncommon resource fetch → short-lived child process executions from user browser context → file writes in temp directories → anomalous outbound C2-like connections.
AN0500 Analytic 0500
Correlated evidence where Safari/Chrome/WebKit-based processes issue network requests for uncommon or obfuscated JS resources followed by spawning of script interpreters, launchd or ad-hoc binaries, unusual child processes, or dynamic library loads into browser processes. Defender sees: proxy/HTTP logs with suspicious resource content + unifiedlogs/ASL showing browser/plugin crashes or extension loads + process events indicating child process creation and file writes to /var/folders or /tmp shortly after the fetch.
AN0501 Analytic 0501
Post-compromise identity & session anomalies that follow a drive-by compromise: token reuse from new/unfamiliar IPs, anomalous sign-in patterns for previously inactive users, unexpected consent/grant events, or provisioning changes. Defender sees an endpoint/browser compromise (network + endpoint signals) followed by unusual IdP events: new refresh token issuance, consent/consent-grant events, odd MFA bypass patterns, or unusual OAuth client registrations.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Application Log Content · DC0038
- File Creation · DC0039
- Logon Session Creation · DC0067
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Process Creation · DC0032
- Process Modification · DC0020
- User Account Authentication · DC0002
- User Account Metadata · DC0013
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Axiom · G0001
- APT28 · G0007
- Turla · G0010
- Darkhotel · G0012
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Dragonfly · G0035
- Patchwork · G0040
- RTM · G0048
- APT32 · G0050
- PROMETHIUM · G0056
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- Leviathan · G0065
- Elderwood · G0066
- APT37 · G0067
- PLATINUM · G0068
- Dark Caracal · G0070
- APT19 · G0073
- Leafminer · G0077
- APT38 · G0082
- Machete · G0095
- Windshift · G0112
- Windigo · G0124
- Transparent Tribe · G0134
- Andariel · G0138
- Earth Lusca · G1006
- CURIUM · G1012
- Mustard Tempest · G1020
- Daggerfly · G1034
- Winter Vivern · G1035
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.