T1189 Drive-by Compromise
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., [Drive-by Target](https://attack.mitre.org/techniques/T1608/004)), including: * A legitimate website is compromised, allowing adversaries to inject malicious code * Script files served to a legitimate website from a…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Cross Site Scripting Stringshightest · webserver
- Flash Player Update from Suspicious Locationhightest · proxy
- Suspicious Browser Child Process - MacOSmediumtest · macos
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.