Techniques › T1189 › AN0501
AN0501 Analytic 0501
Identity Provider · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Post-compromise identity & session anomalies that follow a drive-by compromise: token reuse from new/unfamiliar IPs, anomalous sign-in patterns for previously inactive users, unexpected consent/grant events, or provisioning changes. Defender sees an endpoint/browser compromise (network + endpoint signals) followed by unusual IdP events: new refresh token issuance, consent/consent-grant events, odd MFA bypass patterns, or unusual OAuth client registrations.</p>
- Detects
- T1189 Drive-by Compromise
- Part of
- DET0176 Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189)
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| azure:signinlogs | SignIn: Sign-ins flagged as atypical (new geographic region, unfamiliar device id) shortly after correlated endpoint/browser compromise times | DC0002 User Account Authentication |
| m365:unified | Application Consent grants, new OAuth client registrations, or unusual admin-level activities executed by a user account shortly after suspected drive-by compromise | DC0038 Application Log Content |
| saas:auth | Refresh token issuance or refresh token usage from new IPs or user agents | DC0013 User Account Metadata |
| AWS:CloudTrail | ConsoleLogin: If IdP backed by cloud provider, Console login from new IP/agent after correlated endpoint compromise | DC0067 Logon Session Creation |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
IdpAlertWindow | Time window to correlate IdP events to endpoint compromise alerts (default 30 minutes to 2 hours). |
HighRiskCountryList | List of countries/IP zones considered high risk for sign-ins; used to tune geo-anomalies. |
DeviceTrustLevel | Device trust scoring thresholds that influence whether a sign-in is considered suspicious. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2010-0188 | Adobe Reader and Acrobat | Mapped |
| CVE-2010-1297 | Adobe Flash Player | Mapped |
| CVE-2012-2034 | Adobe Flash Player | Mapped |
| CVE-2012-5054 | Adobe Flash Player | Mapped |
| CVE-2014-8439 | Adobe Flash Player | Mapped |
| CVE-2015-0310 | Adobe Flash Player | Mapped |
| CVE-2015-0313 | Adobe Flash Player | Mapped |
| CVE-2015-3043 | Adobe Flash Player | Mapped |
| CVE-2015-8651 | Adobe Flash Player | Mapped |
| CVE-2016-1019 | Adobe Flash Player | Mapped |
| CVE-2016-7855 | Adobe Flash Player | Mapped |
| CVE-2023-43770 | Roundcube Webmail | Mapped |
| CVE-2023-7024 | Google Chromium WebRTC | Mapped |
| CVE-2024-38112 | Microsoft Windows | Mapped |
| CVE-2024-4671 | Google Chromium | Mapped |
| CVE-2024-4947 | Google Chromium V8 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | Mapped |
| CVE-2025-24201 | Apple Multiple Products | Mapped |
| CVE-2025-5419 | Google Chromium V8 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | Mapped |
| CVE-2025-6558 | Google Chromium | Mapped |