MITRE ATT&CK technique
Drive-by Compromise detection rulesT1189
Drive-by Compromise (T1189) is a MITRE ATT&CK technique in the Initial Access tactic. This page lists the 3 community-maintained Sigma detection rules in the library mapped to T1189 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target macos.
T1189 on attack.mitre.org3 rules
Top products
Tactic
Cross Site Scripting Strings
highDetects XSS attempts injected via GET requests in access logs
webserver
Flash Player Update from Suspicious Location
highDetects a flashplayer update from an unofficial location
proxy
Suspicious Browser Child Process - MacOS
mediumDetects suspicious child processes spawned from browsers. This could be a result of a potential web browser exploitation.
macos · process_creation