Drive-by Compromise T1189

Tactic: Initial Access

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:

Events covered

9 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 52 rules share fields, values, and exclusions.

Fields filtered most (101 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType11eq 10, starts_with 1block.url, start, FilteredWebsites_Event, Image loaded, download
process_name8eq 5, in 2, wildcard 2chrome.exe, promecefpluginhost.exe, *brave*.exe, *chrome*.exe, *discord*.exe
CommandLine4contains 3, eq 1, is_not_null 1, is_null 1, match 1, wildcard 1*ms-officecmd*LaunchOfficeAppForResult*--gpu-launcher*, --defaults-torrc, /applications/google..., /applications/google..., action identificator
DvcAction4eq 3, starts_with 1BLOCK_, allowed, block_admin_file_type, file_downloaded
File4in 4, is_not_null 1id_rsa, passwd, shadow, hosts
host.os.type4eq 4
parent_process_name4eq 3, wildcard 1Google Chrome, Google Chrome Helper*, Microsoft Edge, explorer.exe, foxmail.exe
AmpFileName3is_not_null 3
Image3ends_with 1, eq 1, wildcard 1/bash, /curl, /dash, ?:\users\*\downloads\*, c:\program files (x86)\internet explorer\iexplore.exe
RuleName3eq 2, ne 1Cybereinforce Threat Intelligence
count_3gt 2, ge 110, 1
event.type3eq 2, in 1start, process_started
Category2eq 2ApplicationGatewayFirewallLog, frontdoorwebapplicationfirewalllog
DeviceEventClassID2eq 1, starts_with 140, 4001
DeviceVendor2eq 2RidgeSecurity

Top indicator values (253 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypeeq
block.url
57
EventTypeeq
start
2392
Filein
id_rsa
44
Filein
passwd
44
Filein
shadow
44
DeviceVendoreq
RidgeSecurity
22
ImageLoadedwildcard
?:\users\*\appdata\local\temp\wps\inetcache\*
22
IsIoceq
true
23
RuleNameeq
Cybereinforce Threat Intelligence
22
event.typeeq
start
21087
process.Ext.api.nameeq
VirtualProtect
219
process_nameeq
promecefpluginhost.exe
22
process_namein
chrome.exe
218
process_namein
iexplore.exe
25
process_namein
msedge.exe
217
Actioneq
Blocked
15
Actioneq
Matched
15
Activeeq
true
170
AmpScanningVerdictin
2
1
AmpScanningVerdictin
3
1
BlockCountge
15
1
BlockDaysge
3
1
Blocked_Reasoncontains
xss
1
Categoryeq
ApplicationGatewayFirewallLog
12
Categoryeq
frontdoorwebapplicationfirewalllog
14
Classificationeq
Enter classification
1
CommandLinecontains
--defaults-torrc
1
CommandLinecontains
/chromerecovery
1
CommandLinecontains
/library/application support/google/chrome/recovery/
1
CommandLinecontains
/users/
12

Exclusions (51 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.thread.Ext.call_stack_final_user_module.protection_provenancewildcard
Kernel
2
process.thread.Ext.call_stack_final_user_module.protection_provenancewildcard
Kernel|*
2
AmpFileNameends_with
.exe
1
CommandLinecontains
--defaults-torrc
1
CommandLinecontains
/chromerecovery
1
CommandLinecontains
/library/application support/google/chrome/recovery/
1
CommandLinecontains
/users/
1
CommandLinecontains
hw.model
1
CommandLinecontains
ioplatformexpertdevice
1
CommandLinematch
/applications/google chrome.app/contents/frameworks/google chrome...
1
CommandLinematch
/applications/google chrome.app/contents/frameworks/google chrome...
1
CommandLinematch
/library/application support/microsoft/mau*/microsoft...
1
CommandLinematch
/volumes/google chrome/google chrome.app/contents/frameworks/*/resources/install.sh
1
Imagewildcard
?:\program files (x86)\*.exe
1
Imagewildcard
?:\program files\*.exe
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 3 rules

Elastic 12 rules

Splunk 2 rules

Kusto 35 rules