Techniques › T1189 › AN0498
AN0498 Analytic 0498
Windows · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Correlated evidence of anomalous browser/network behavior (suspicious external resource fetches and script injection patterns) followed by atypical child processes, ephemeral execution contexts, memory modification or process injection, and unexpected file drops. Defender sees network requests to previously unseen/suspicious domains or resources + browser process spawning unusual children or loading unsigned modules + file writes or registry changes shortly after those requests.</p>
- Detects
- T1189 Drive-by Compromise
- Part of
- DET0176 Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189)
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| WinEventLog:Security | EventCode=4624, 4648 | DC0067 Logon Session Creation |
| WinEventLog:Security | EventCode=4688 | DC0032 Process Creation |
| WinEventLog:Sysmon | EventCode=3, 22 | DC0082 Network Connection Creation |
| WinEventLog:Application | Browser or plugin/application logs showing script errors, plugin enumerations, or unusual extension load events | DC0038 Application Log Content |
| etw:Microsoft-Windows-Kernel-Process | Memory Modification / Unmapped module load or suspicious RWX allocations in the process space of a browser process | DC0020 Process Modification |
| WinEventLog:Sysmon | EventCode=11 | DC0039 File Creation |
| NSM:Flow | http.request: HTTP requests and responses for specific script resources, unexpected content-types (application/octet-stream for script URLs), suspicious referrers, or obfuscated javascript resources | DC0085 Network Traffic Content |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
TimeWindow | Correlation time window between suspicious network fetch and subsequent process/file events. Tweak for environment latency and caching; default 2 minutes. |
KnownGoodDomainsList | Allowlist of high-volume, benign domains used by corporate sites or CDNs to reduce false positives. |
PayloadEntropyThreshold | Entropy threshold for downloaded script/binary content to surface likely obfuscated/packed payloads. |
UserContext | Exclude or treat differently known administrative service accounts or build machines versus end-user contexts. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2010-0188 | Adobe Reader and Acrobat | Mapped |
| CVE-2010-1297 | Adobe Flash Player | Mapped |
| CVE-2012-2034 | Adobe Flash Player | Mapped |
| CVE-2012-5054 | Adobe Flash Player | Mapped |
| CVE-2014-8439 | Adobe Flash Player | Mapped |
| CVE-2015-0310 | Adobe Flash Player | Mapped |
| CVE-2015-0313 | Adobe Flash Player | Mapped |
| CVE-2015-3043 | Adobe Flash Player | Mapped |
| CVE-2015-8651 | Adobe Flash Player | Mapped |
| CVE-2016-1019 | Adobe Flash Player | Mapped |
| CVE-2016-7855 | Adobe Flash Player | Mapped |
| CVE-2023-43770 | Roundcube Webmail | Mapped |
| CVE-2023-7024 | Google Chromium WebRTC | Mapped |
| CVE-2024-38112 | Microsoft Windows | Mapped |
| CVE-2024-4671 | Google Chromium | Mapped |
| CVE-2024-4947 | Google Chromium V8 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | Mapped |
| CVE-2025-24201 | Apple Multiple Products | Mapped |
| CVE-2025-5419 | Google Chromium V8 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | Mapped |
| CVE-2025-6558 | Google Chromium | Mapped |