kevmap

TechniquesT1189 › AN0501

AN0501 Analytic 0501

Identity Provider · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Post-compromise identity & session anomalies that follow a drive-by compromise: token reuse from new/unfamiliar IPs, anomalous sign-in patterns for previously inactive users, unexpected consent/grant events, or provisioning changes. Defender sees an endpoint/browser compromise (network + endpoint signals) followed by unusual IdP events: new refresh token issuance, consent/consent-grant events, odd MFA bypass patterns, or unusual OAuth client registrations.</p>
Detects
T1189 Drive-by Compromise
Part of
DET0176 Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
azure:signinlogsSignIn: Sign-ins flagged as atypical (new geographic region, unfamiliar device id) shortly after correlated endpoint/browser compromise timesDC0002 User Account Authentication
m365:unifiedApplication Consent grants, new OAuth client registrations, or unusual admin-level activities executed by a user account shortly after suspected drive-by compromiseDC0038 Application Log Content
saas:authRefresh token issuance or refresh token usage from new IPs or user agentsDC0013 User Account Metadata
AWS:CloudTrailConsoleLogin: If IdP backed by cloud provider, Console login from new IP/agent after correlated endpoint compromiseDC0067 Logon Session Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
IdpAlertWindowTime window to correlate IdP events to endpoint compromise alerts (default 30 minutes to 2 hours).
HighRiskCountryListList of countries/IP zones considered high risk for sign-ins; used to tune geo-anomalies.
DeviceTrustLevelDevice trust scoring thresholds that influence whether a sign-in is considered suspicious.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2010-0188Adobe Reader and AcrobatMapped
CVE-2010-1297Adobe Flash PlayerMapped
CVE-2012-2034Adobe Flash PlayerMapped
CVE-2012-5054Adobe Flash PlayerMapped
CVE-2014-8439Adobe Flash PlayerMapped
CVE-2015-0310Adobe Flash PlayerMapped
CVE-2015-0313Adobe Flash PlayerMapped
CVE-2015-3043Adobe Flash PlayerMapped
CVE-2015-8651Adobe Flash PlayerMapped
CVE-2016-1019Adobe Flash PlayerMapped
CVE-2016-7855Adobe Flash PlayerMapped
CVE-2023-43770Roundcube WebmailMapped
CVE-2023-7024Google Chromium WebRTCMapped
CVE-2024-38112Microsoft WindowsMapped
CVE-2024-4671Google ChromiumMapped
CVE-2024-4947Google Chromium V8Mapped
CVE-2024-5274Google Chromium V8Mapped
CVE-2025-24201Apple Multiple ProductsMapped
CVE-2025-5419Google Chromium V8Mapped
CVE-2025-6554Google Chromium V8Mapped
CVE-2025-6558Google ChromiumMapped