Drive-by Compromise T1189

Tactic: Initial Access

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:

Events covered

9 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 46 rules share fields, values, and exclusions.

Fields filtered most (89 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
process_name8eq 5, in 2, wildcard 2chrome.exe, promecefpluginhost.exe, *brave*.exe, *chrome*.exe, *discord*.exe
EventType6eq 5, starts_with 1start, FilteredWebsites_Event, Image loaded, download, proxylogs
CommandLine4contains 3, eq 1, is_not_null 1, is_null 1, match 1, wildcard 1*ms-officecmd*LaunchOfficeAppForResult*--gpu-launcher*, --defaults-torrc, /applications/google..., /applications/google..., action identificator
DvcAction4eq 3, starts_with 1BLOCK_, allowed, block_admin_file_type, file_downloaded
File4in 4, is_not_null 1id_rsa, passwd, shadow, hosts
host.os.type4eq 4
parent_process_name4eq 3, wildcard 1Google Chrome, Google Chrome Helper*, Microsoft Edge, explorer.exe, foxmail.exe
AmpFileName3is_not_null 3
Image3ends_with 1, eq 1, wildcard 1/bash, /curl, /dash, ?:\users\*\downloads\*, c:\program files (x86)\internet explorer\iexplore.exe
count_3gt 2, ge 110, 1
event.type3eq 2, in 1start, process_started
Category2eq 2ApplicationGatewayFirewallLog, frontdoorwebapplicationfirewalllog
DeviceEventClassID2eq 1, starts_with 140, 4001
DeviceVendor2eq 2RidgeSecurity
Hashes2is_not_null 2

Top indicator values (243 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
Filein
id_rsa
44
Filein
passwd
44
Filein
shadow
44
DeviceVendoreq
RidgeSecurity
22
EventTypeeq
start
2391
ImageLoadedwildcard
?:\users\*\appdata\local\temp\wps\inetcache\*
22
event.typeeq
start
21078
process.Ext.api.nameeq
VirtualProtect
219
process_nameeq
promecefpluginhost.exe
22
process_namein
chrome.exe
218
process_namein
iexplore.exe
25
process_namein
msedge.exe
217
Actioneq
Blocked
15
Actioneq
Matched
15
Activeeq
true
170
AmpScanningVerdictin
2
1
AmpScanningVerdictin
3
1
Blocked_Reasoncontains
xss
1
Categoryeq
ApplicationGatewayFirewallLog
12
Categoryeq
frontdoorwebapplicationfirewalllog
14
Classificationeq
Enter classification
1
CommandLinecontains
--defaults-torrc
1
CommandLinecontains
/chromerecovery
1
CommandLinecontains
/library/application support/google/chrome/recovery/
1
CommandLinecontains
/users/
12
CommandLinecontains
action identificator
1
CommandLinecontains
anti-robot test
1
CommandLinecontains
captcha verif
1
CommandLinecontains
click ok to
1
CommandLinecontains
cloudflare id
1

Exclusions (51 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.thread.Ext.call_stack_final_user_module.protection_provenancewildcard
Kernel
2
process.thread.Ext.call_stack_final_user_module.protection_provenancewildcard
Kernel|*
2
AmpFileNameends_with
.exe
1
CommandLinecontains
--defaults-torrc
1
CommandLinecontains
/chromerecovery
1
CommandLinecontains
/library/application support/google/chrome/recovery/
1
CommandLinecontains
/users/
1
CommandLinecontains
hw.model
1
CommandLinecontains
ioplatformexpertdevice
1
CommandLinematch
/applications/google chrome.app/contents/frameworks/google chrome...
1
CommandLinematch
/applications/google chrome.app/contents/frameworks/google chrome...
1
CommandLinematch
/library/application support/microsoft/mau*/microsoft...
1
CommandLinematch
/volumes/google chrome/google chrome.app/contents/frameworks/*/resources/install.sh
1
Imagewildcard
?:\program files (x86)\*.exe
1
Imagewildcard
?:\program files\*.exe
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 3 rules

Elastic 11 rules

Splunk 2 rules

Kusto 30 rules