kevmap

TechniquesT1189 › AN0500

AN0500 Analytic 0500

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Correlated evidence where Safari/Chrome/WebKit-based processes issue network requests for uncommon or obfuscated JS resources followed by spawning of script interpreters, launchd or ad-hoc binaries, unusual child processes, or dynamic library loads into browser processes. Defender sees: proxy/HTTP logs with suspicious resource content + unifiedlogs/ASL showing browser/plugin crashes or extension loads + process events indicating child process creation and file writes to /var/folders or /tmp shortly after the fetch.</p>
Detects
T1189 Drive-by Compromise
Part of
DET0176 Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogLogs from unifiedlogging that show browser crashes, plugin enumerations, extension installs or errors around the same time as suspicious network fetchesDC0038 Application Log Content
macos:unifiedlogprocess_create: Process creation where parent is Safari/Google Chrome and child is script interpreter or signed-but-unusual helper binaryDC0032 Process Creation
macos:unifiedlogNew files written to /var/folders, /tmp, ~/Library/Caches, or ~/Downloads by browser context or its childrenDC0039 File Creation
NSM:FlowHTTP/HTTPS requests for script resources flagged by content inspection (excessive obfuscation, eval usage, unusual redirects)DC0085 Network Traffic Content
macos:unifiedlogAnomalous dyld dynamic library loads or RWX memory mappings in browser processDC0020 Process Modification

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
SleepyUserThresholdVolume thresholds for interactive user browsing vs. automated systems (e.g., shared kiosks) — tune to reduce FP in heavy-browsing employees.
ExtensionInstallPolicyPolicy setting that influences how extension installs are treated: strict policy reduces FP from known extension behavior.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2010-0188Adobe Reader and AcrobatMapped
CVE-2010-1297Adobe Flash PlayerMapped
CVE-2012-2034Adobe Flash PlayerMapped
CVE-2012-5054Adobe Flash PlayerMapped
CVE-2014-8439Adobe Flash PlayerMapped
CVE-2015-0310Adobe Flash PlayerMapped
CVE-2015-0313Adobe Flash PlayerMapped
CVE-2015-3043Adobe Flash PlayerMapped
CVE-2015-8651Adobe Flash PlayerMapped
CVE-2016-1019Adobe Flash PlayerMapped
CVE-2016-7855Adobe Flash PlayerMapped
CVE-2023-43770Roundcube WebmailMapped
CVE-2023-7024Google Chromium WebRTCMapped
CVE-2024-38112Microsoft WindowsMapped
CVE-2024-4671Google ChromiumMapped
CVE-2024-4947Google Chromium V8Mapped
CVE-2024-5274Google Chromium V8Mapped
CVE-2025-24201Apple Multiple ProductsMapped
CVE-2025-5419Google Chromium V8Mapped
CVE-2025-6554Google Chromium V8Mapped
CVE-2025-6558Google ChromiumMapped