kevmap

TechniquesT1189 › AN0499

AN0499 Analytic 0499

Linux · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Correlated evidence of browser or webview fetches to uncommon domains or mutated JS resources (proxy/NGFW logs + Zeek/HTTP logs) followed by unexpected interpreters or script engines executing (python, ruby, sh) spawned from browser processes or user sessions, rapid on-disk staging in /tmp, and outbound connections that deviate from baseline. Defender sees: uncommon resource fetch → short-lived child process executions from user browser context → file writes in temp directories → anomalous outbound C2-like connections.</p>
Detects
T1189 Drive-by Compromise
Part of
DET0176 Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
auditd:SYSCALLexecve: execve calls where a browser/webview process is parent and child is interpreter (python, sh, ruby) or downloader (curl, wget)DC0032 Process Creation
linux:syslogApplication or browser logs (webview errors, plugin enumerations) indicating suspicious script evaluation or plugin loadsDC0038 Application Log Content
NSM:Flowhttp::response: HTTP responses with suspicious content-type for scripts, long obfuscated javascript bodies, or redirects to exploit kit domainsDC0085 Network Traffic Content
linux:SysmonNew files in /tmp, /var/tmp, $HOME/.cache, executed within TimeWindow after browser HTTP fetchDC0039 File Creation
NSM:ConnectionsOutbound connections from newly spawned child processes or from the browser to uncommon endpoints or on anomalous portsDC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TempPathPatternsPaths used for staging differ by distro and package manager; tune to include company-specific temp paths or exclude known benign build machines.
UserShellWhitelistWhitelist known server/service accounts or CI/CD runners where shell executions are expected.
DomainRarityThresholdThreshold for flagging domains based on internal popularity vs global rarity.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2010-0188Adobe Reader and AcrobatMapped
CVE-2010-1297Adobe Flash PlayerMapped
CVE-2012-2034Adobe Flash PlayerMapped
CVE-2012-5054Adobe Flash PlayerMapped
CVE-2014-8439Adobe Flash PlayerMapped
CVE-2015-0310Adobe Flash PlayerMapped
CVE-2015-0313Adobe Flash PlayerMapped
CVE-2015-3043Adobe Flash PlayerMapped
CVE-2015-8651Adobe Flash PlayerMapped
CVE-2016-1019Adobe Flash PlayerMapped
CVE-2016-7855Adobe Flash PlayerMapped
CVE-2023-43770Roundcube WebmailMapped
CVE-2023-7024Google Chromium WebRTCMapped
CVE-2024-38112Microsoft WindowsMapped
CVE-2024-4671Google ChromiumMapped
CVE-2024-4947Google Chromium V8Mapped
CVE-2024-5274Google Chromium V8Mapped
CVE-2025-24201Apple Multiple ProductsMapped
CVE-2025-5419Google Chromium V8Mapped
CVE-2025-6554Google Chromium V8Mapped
CVE-2025-6558Google ChromiumMapped