T1189 Drive-by Compromise
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., [Drive-by Target](https://attack.mitre.org/techniques/T1608/004)), including: * A legitimate website is compromised, allowing adversaries to inject malicious code * Script files served to a legitimate website from a…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Cross Site Scripting Stringshightest · webserver
- Flash Player Update from Suspicious Locationhightest · proxy
- Suspicious Browser Child Process - MacOSmediumtest · macos
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.