Techniques › T1608 › T1608.004
T1608.004 Drive-by Target
resource development — PRE · attack.mitre.org · JSON
1
MITRE detection strategy
1
analytics
0
Sigma rules tagged attack.t1608.004
0
KEV CVEs mapped here
<p>Adversaries may prepare an operational environment to infect systems that visit a website over the normal course of browsing. Endpoint systems may be compromised through browsing to adversary controlled sites, as in Drive-by Compromise. In such cases, the user's web browser is typically targeted for exploitation (often not requiring any extra user interaction once landing on the site), but adversaries may also set up websites for non-exploitation behavior such as Application Access Token. Prior to Drive-by Compromise, adversaries must stage resources needed to deliver that exploit to users who browse to an adversary controlled site. Drive-by content can be staged on adversary controlled infrastructure that has been acquired (Acquire Infrastructure) or previously compromised (Compromise Infrastructure).</p><p>Adversaries may upload or inject malicious web content, such as JavaScript, into websites. This may be done in a number of ways, including:</p>
- <li>Inserting malicious scripts into web pages or other user controllable web content such as forum posts</li><li>Modifying script files served to websites from publicly writeable cloud storage buckets</li><li>Crafting malicious web advertisements and purchasing ad space on a website through legitimate ad providers (i.e., Malvertising)</li>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0825 Detection of Drive-by Target v1.0
AN1957 PREIf infrastructure or patterns in the malicious web content utilized to deliver a Drive-by Compromise have been previously identified, internet scanning may uncover when an adversary has staged web content for use in a strategic web compromise. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on other phases of the adversary lifecycle, such as Drive-by Compromise or Exploitation for Client Execution.
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1608.004
No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.
Rules tagged at the parent level (attack.t1608) 2
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
· 2021-12-27 (modified 2022-08-02) · logsource: product=windows category=process_creation · 00d49ed5-4491-4271-a8db-650a4ef6f8c1
Detects suspicious ways to download files from Microsoft domains that are used to store attachments in Emails or OneNote documents
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)
· 2021-04-12 (modified 2022-11-27) · logsource: product=windows category=registry_event · ac8866c7-ce44-46fd-8c17-b24acff96ca8
Detects the installation of the Azure Hybrid Connection Manager service to allow remote code execution from Azure function.