Techniques › T1189 › AN0500
AN0500 Analytic 0500
macOS · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Correlated evidence where Safari/Chrome/WebKit-based processes issue network requests for uncommon or obfuscated JS resources followed by spawning of script interpreters, launchd or ad-hoc binaries, unusual child processes, or dynamic library loads into browser processes. Defender sees: proxy/HTTP logs with suspicious resource content + unifiedlogs/ASL showing browser/plugin crashes or extension loads + process events indicating child process creation and file writes to /var/folders or /tmp shortly after the fetch.</p>
- Detects
- T1189 Drive-by Compromise
- Part of
- DET0176 Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189)
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| macos:unifiedlog | Logs from unifiedlogging that show browser crashes, plugin enumerations, extension installs or errors around the same time as suspicious network fetches | DC0038 Application Log Content |
| macos:unifiedlog | process_create: Process creation where parent is Safari/Google Chrome and child is script interpreter or signed-but-unusual helper binary | DC0032 Process Creation |
| macos:unifiedlog | New files written to /var/folders, /tmp, ~/Library/Caches, or ~/Downloads by browser context or its children | DC0039 File Creation |
| NSM:Flow | HTTP/HTTPS requests for script resources flagged by content inspection (excessive obfuscation, eval usage, unusual redirects) | DC0085 Network Traffic Content |
| macos:unifiedlog | Anomalous dyld dynamic library loads or RWX memory mappings in browser process | DC0020 Process Modification |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
SleepyUserThreshold | Volume thresholds for interactive user browsing vs. automated systems (e.g., shared kiosks) — tune to reduce FP in heavy-browsing employees. |
ExtensionInstallPolicy | Policy setting that influences how extension installs are treated: strict policy reduces FP from known extension behavior. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2010-0188 | Adobe Reader and Acrobat | Mapped |
| CVE-2010-1297 | Adobe Flash Player | Mapped |
| CVE-2012-2034 | Adobe Flash Player | Mapped |
| CVE-2012-5054 | Adobe Flash Player | Mapped |
| CVE-2014-8439 | Adobe Flash Player | Mapped |
| CVE-2015-0310 | Adobe Flash Player | Mapped |
| CVE-2015-0313 | Adobe Flash Player | Mapped |
| CVE-2015-3043 | Adobe Flash Player | Mapped |
| CVE-2015-8651 | Adobe Flash Player | Mapped |
| CVE-2016-1019 | Adobe Flash Player | Mapped |
| CVE-2016-7855 | Adobe Flash Player | Mapped |
| CVE-2023-43770 | Roundcube Webmail | Mapped |
| CVE-2023-7024 | Google Chromium WebRTC | Mapped |
| CVE-2024-38112 | Microsoft Windows | Mapped |
| CVE-2024-4671 | Google Chromium | Mapped |
| CVE-2024-4947 | Google Chromium V8 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | Mapped |
| CVE-2025-24201 | Apple Multiple Products | Mapped |
| CVE-2025-5419 | Google Chromium V8 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | Mapped |
| CVE-2025-6558 | Google Chromium | Mapped |