kevmap

TechniquesT1189 › AN0498

AN0498 Analytic 0498

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Correlated evidence of anomalous browser/network behavior (suspicious external resource fetches and script injection patterns) followed by atypical child processes, ephemeral execution contexts, memory modification or process injection, and unexpected file drops. Defender sees network requests to previously unseen/suspicious domains or resources + browser process spawning unusual children or loading unsigned modules + file writes or registry changes shortly after those requests.</p>
Detects
T1189 Drive-by Compromise
Part of
DET0176 Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SecurityEventCode=4624, 4648DC0067 Logon Session Creation
WinEventLog:SecurityEventCode=4688DC0032 Process Creation
WinEventLog:SysmonEventCode=3, 22DC0082 Network Connection Creation
WinEventLog:ApplicationBrowser or plugin/application logs showing script errors, plugin enumerations, or unusual extension load eventsDC0038 Application Log Content
etw:Microsoft-Windows-Kernel-ProcessMemory Modification / Unmapped module load or suspicious RWX allocations in the process space of a browser processDC0020 Process Modification
WinEventLog:SysmonEventCode=11DC0039 File Creation
NSM:Flowhttp.request: HTTP requests and responses for specific script resources, unexpected content-types (application/octet-stream for script URLs), suspicious referrers, or obfuscated javascript resourcesDC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TimeWindowCorrelation time window between suspicious network fetch and subsequent process/file events. Tweak for environment latency and caching; default 2 minutes.
KnownGoodDomainsListAllowlist of high-volume, benign domains used by corporate sites or CDNs to reduce false positives.
PayloadEntropyThresholdEntropy threshold for downloaded script/binary content to surface likely obfuscated/packed payloads.
UserContextExclude or treat differently known administrative service accounts or build machines versus end-user contexts.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2010-0188Adobe Reader and AcrobatMapped
CVE-2010-1297Adobe Flash PlayerMapped
CVE-2012-2034Adobe Flash PlayerMapped
CVE-2012-5054Adobe Flash PlayerMapped
CVE-2014-8439Adobe Flash PlayerMapped
CVE-2015-0310Adobe Flash PlayerMapped
CVE-2015-0313Adobe Flash PlayerMapped
CVE-2015-3043Adobe Flash PlayerMapped
CVE-2015-8651Adobe Flash PlayerMapped
CVE-2016-1019Adobe Flash PlayerMapped
CVE-2016-7855Adobe Flash PlayerMapped
CVE-2023-43770Roundcube WebmailMapped
CVE-2023-7024Google Chromium WebRTCMapped
CVE-2024-38112Microsoft WindowsMapped
CVE-2024-4671Google ChromiumMapped
CVE-2024-4947Google Chromium V8Mapped
CVE-2024-5274Google Chromium V8Mapped
CVE-2025-24201Apple Multiple ProductsMapped
CVE-2025-5419Google Chromium V8Mapped
CVE-2025-6554Google Chromium V8Mapped
CVE-2025-6558Google ChromiumMapped