Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Initial Access/ T1189

T1189Drive-by Compromise

T1189 — Drive-by Compromise is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 31 detection use cases covering it and 9 threat-intel articles citing it.

Initial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
31Use cases
9Articles
0Sub-techniques
1Tactic

Use cases covering this technique (31)

Splunk XSS Privilege Escalation via Custom Urls in Dashboard ESCU actions · hunting P Detect hosts connecting to dynamic domain providers ESCU actions · alerting P Persistent XSS in RapidDiag through User Interface Views ESCU actions · alerting P Splunk CSRF in the SSG kvstore Client Endpoint ESCU actions · alerting P Splunk list all nonstandard admin accounts ESCU actions · hunting P Splunk Persistent XSS via Props Conf ESCU actions · hunting P Splunk Persistent XSS via Scheduled Views ESCU actions · hunting P Splunk Persistent XSS Via URL Validation Bypass W Dashboard ESCU actions · hunting P Splunk Reflected XSS in the templates lists radio ESCU actions · hunting P Splunk Reflected XSS on App Search Table Endpoint ESCU actions · hunting P Splunk Stored XSS conf-web Settings on Premises ESCU actions · hunting P Splunk Stored XSS via Data Model objectName Field ESCU actions · hunting P Splunk Stored XSS via Specially Crafted Bulletin Message ESCU actions · hunting P Splunk Unauthorized Experimental Items Creation ESCU actions · hunting P Splunk unnecessary file extensions allowed by lookup table uploads ESCU actions · alerting P Splunk XSS in Highlighted JSON Events ESCU actions · hunting P Splunk XSS in Monitoring Console ESCU actions · alerting P Splunk XSS in Save table dialog header in search page ESCU actions · hunting P Splunk XSS Via External Urls in Dashboards SSRF ESCU actions · hunting P Splunk XSS via View ESCU actions · hunting P [LLM] Vulnerable Firefox exposed to CVE-2026-10702 JIT RCE (147 through 151.0.2) Bespoke exploit · alerting DSP [LLM] Outdated Tor Browser bundling vulnerable Firefox (CVE-2026-10702 exposure) Bespoke exploit · hunting DSPDDCS [LLM] SourTrade malvertising infrastructure contact (campaign domains + Bun-runtime host) Bespoke delivery · alerting DSΣPDDCS [LLM] SourTrade ServiceWorker build-instruction fetch (/config + /sw.js on campaign domains) Bespoke delivery · hunting DSΣP [LLM] NodeBB remote federated-user profile lookup (ActivityPub XSS #1 trigger) Bespoke delivery · hunting SΣP [LLM] Credential-phishing form injection via reflected XSS in MantisBT install.php (CVE-2026-52881) Bespoke delivery · alerting SΣP [LLM] Joro proxy-mode confused-deputy: browser POSTs to loopback API 127.0.0.1:9090 (CVE-2026-53649) Bespoke delivery · hunting DSΣPCS [LLM] Browser-dropped .bin password-protected archive (fake software crack lure) Bespoke delivery · hunting DSΣPDDCS [LLM] Browser load of Beamglea redirect-* or mad-* package script from unpkg.com Bespoke exploit · alerting DSΣPDDCS [LLM] Polyfill.io supply-chain compromise: egress to Funnull-controlled CDN cluster Bespoke delivery · alerting DSΣPDDCS [LLM] Unpatched libwebp-bundling apps in software inventory (Chrome, Electron, 1Password, ImageMagick, GIMP, ffmpeg) Bespoke weapon · hunting DSP

Articles citing this technique (9)