What is a drive-by compromise?¶
A drive-by compromise occurs when loading online content leads to unauthorised activity on a device, sometimes without a deliberate download or further user action. Visiting a page is not itself proof that compromise occurred.
The delivery may involve a compromised site, malicious advertising, redirects, browser exploitation, deceptive update prompts or scripts that retrieve another stage.
Reconstruct delivery and device effect¶
Establish how the user reached the page, the exact time, browser version and content loaded. Browser history, cache and downloads can be aligned with DNS, proxy, endpoint, memory and security records.
Separate the visit, redirect, delivery, execution and resulting activity. A required vulnerability may not have existed; the content may have been blocked; or the page may have served different material according to location, device or profile. The absence of a downloaded executable does not exclude script or memory-based execution.
Preserve a changing online route¶
Dynamic advertising and third-party scripts may make later reproduction impossible. Preserve URLs, provider and campaign identifiers, response content and redirect records where available. A screenshot records appearance but not the code or full delivery chain.
Do not assume the website owner created the malicious content. The site, advertising exchange or third-party supplier may itself have been compromised. Attribution requires evidence beyond the fact that content appeared there.
Key takeaway
Prove a drive-by compromise by connecting a particular visit and delivered content to execution and device effects, not from browser history alone.