Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a drive-by compromise?

A drive-by compromise occurs when loading online content leads to unauthorised activity on a device, sometimes without a deliberate download or further user action. Visiting a page is not itself proof that compromise occurred.

The delivery may involve a compromised site, malicious advertising, redirects, browser exploitation, deceptive update prompts or scripts that retrieve another stage.

VisitBrowser loads online contentHistory can show the page or request.
DeliveryRedirect or harmful content reaches browserProxy, cache or response data may preserve the route.
ExecutionBrowser or another component processes itEndpoint or memory evidence is needed for success.
EffectUnauthorised activity followsProcesses, files, accounts or network activity show what changed.

Reconstruct delivery and device effect

Establish how the user reached the page, the exact time, browser version and content loaded. Browser history, cache and downloads can be aligned with DNS, proxy, endpoint, memory and security records.

Separate the visit, redirect, delivery, execution and resulting activity. A required vulnerability may not have existed; the content may have been blocked; or the page may have served different material according to location, device or profile. The absence of a downloaded executable does not exclude script or memory-based execution.

Preserve a changing online route

Dynamic advertising and third-party scripts may make later reproduction impossible. Preserve URLs, provider and campaign identifiers, response content and redirect records where available. A screenshot records appearance but not the code or full delivery chain.

Do not assume the website owner created the malicious content. The site, advertising exchange or third-party supplier may itself have been compromised. Attribution requires evidence beyond the fact that content appeared there.

Key takeaway

Prove a drive-by compromise by connecting a particular visit and delivered content to execution and device effects, not from browser history alone.

Reference: CIM-100Cyber Incidents & Offender Methods