Cross-source coverage

T1203 / ATT&CK

Exploitation for Client Execution

129 rules · 126 families across 10 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.

Several types exist:

Browser-based Exploitation

Web browsers are a common target through Drive-by Compromise and Spearphishing Link. Endpoint systems may be compromised through normal web browsing or from certain users being targeted by links in spearphishing emails to adversary controlled sites used to exploit the web browser. These often do not require an action by the user for the exploit to be executed.

Office Applications

Common office and productivity applications such as Microsoft Office are also targeted through Phishing. Malicious files will be transmitted directly as attachments or through links to download them. These require the user to open the document or file for the exploit to run.

Common Third-party Applications

Other applications that are commonly seen or are part of the software deployed in a target network may also be used for exploitation. Applications such as Adobe Reader and Flash, which are common in enterprise environments, have been routinely targeted by adversaries attempting to gain access to systems. Depending on the software and nature of the vulnerability, some may be exploited in the browser or require the user to open a file. For instance, some Flash exploits have been delivered as objects within Microsoft Office documents.

Tactics
Execution
Platforms
Linux · macOS · Windows
Telemetry
WinEventLog:ApplicationWinEventLog:Sysmonlinux:syslogauditd:SYSCALLNetFlow:Flowmacos:unifiedlogfs:fseventsmacos:osqueryNSM:Connections

How MITRE says to detect it DET0287

Exploitation for Client Execution – cross-platform behavior chain (browser/Office/3rd-party apps)

Windows Analytic 0797

Cause→effect chain: (1) A client app (browser, Office, PDF/Flash/reader) experiences a crash/abnormal exit or loads from an unusual location, then (2) drops or modifies a file in user-writable paths, and/or (3) spawns an unexpected child (e.g., powershell/cmd/mshta/rundll32/wscript/installer), and (4) establishes outbound C2-like connections shortly after. Correlate application logs, file writes, process lineage, and network egress within a short window.

  • WinEventLog:Application EventCode=1000
  • WinEventLog:Sysmon EventCode=11
  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=3, 22

Linux Analytic 0798

Cause→effect chain: (1) Browser/Office/reader process logs crash/segfault or abnormal sandbox message, (2) new executable/script/write occurs in $HOME (Downloads, ~/.cache, /tmp), (3) unexpected child like curl/wget/bash/python opens network connections soon after.

  • linux:syslog browser/office crash, segfault, abnormal termination
  • auditd:SYSCALL open
  • auditd:SYSCALL creat
  • auditd:SYSCALL rename,chmod
  • auditd:SYSCALL execve
  • NetFlow:Flow new outbound connections from exploited process tree

macOS Analytic 0799

Cause→effect chain: (1) App crash/abnormal termination in unified logs for Safari/Chrome/Office/Preview, (2) new files/scripts in ~/Library, ~/Downloads, /private/var/folders/*, (3) unexpected child (osascript, zsh, bash, curl) spawned by those apps, (4) new outbound connections.

  • macos:unifiedlog process crash, abort, code signing violations
  • fs:fsevents create/write/rename under user-writable paths
  • macos:osquery exec
  • NSM:Connections new connections from exploited lineage

SigmaHQ/sigma

35 rules
Detection Severity Format
Antivirus - APT Malware Signature Critical Sigma
Antivirus - Exploitation Framework Signature Critical Sigma
Antivirus - Remote Access Tools Signature Critical Sigma
Audit CVE Event Critical Sigma
CVE-2021-31979 CVE-2021-33771 Exploits Critical Sigma
CVE-2021-31979 CVE-2021-33771 Exploits by Sourgum Critical Sigma
Droppers Exploiting CVE-2017-11882 Critical Sigma
Exploit for CVE-2017-8759 Critical Sigma
CVE-2021-26858 Exchange Exploitation High Sigma
CVE-2023-38331 Exploitation Attempt - Suspicious WinRAR Child Process High Sigma

+ 25 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

29 rules
Detection Severity Format
Cupsd or Foomatic-rip Shell Execution High Elastic TOML
Execution of File Written or Modified by Microsoft Office High Elastic TOML
Exploit - Detected - Elastic Endgame High Elastic TOML
Multiple DHCP Servers Responding to the Same Transaction High Elastic TOML
Network Connection by Cups or Foomatic-rip Child High Elastic TOML
Potential CVE-2025-33053 Exploitation High Elastic TOML
Potential Foxmail Exploitation High Elastic TOML
Potential Git CVE-2025-48384 Exploitation High Elastic TOML
Potential JAVA/JNDI Exploitation Attempt High Elastic TOML
Potential Notepad Markdown RCE Exploitation High Elastic TOML

+ 19 more from elastic/detection-rules → showing the 10 highest-severity

elastic/protections-artifacts

21 rules
Detection Severity Format
Execution from a Remote Working Directory Undefined Elastic TOML
Execution of File Written or Modified by Microsoft Equation Editor Undefined Elastic TOML
Microsoft Equation Editor Child Process Undefined Elastic TOML
Potential Browser Exploit via Fake RPC Messages Undefined Elastic TOML
Potential CVE-2024-21412 Exploitation Undefined Elastic TOML
Potential CVE-2025-33053 Exploitation Undefined Elastic TOML
Potential Execution via Archive Exploit Undefined Elastic TOML
Potential Execution via Foxmail Exploitation Undefined Elastic TOML
Potential Execution via WinRAR Exploitation Undefined Elastic TOML
Potential Git CVE-2025-48384 Exploitation Undefined Elastic TOML

+ 11 more from elastic/protections-artifacts → showing the 10 highest-severity

Wazuh Core Ruleset

18 rules
Detection Severity Format
of an user. Critical Wazuh XML
The browser driver has discarded too many mailslot messages High Wazuh XML
The browser driver has received too many illegal datagrams from the remote computer High Wazuh XML
VirusTotal: Alert - - engines detected this file · virustotal.malicious = 1 High Wazuh XML
Auditd: File or a directory access ended abnormally. Medium Wazuh XML
Cylance: File is quarantined. · cylance_events.eventstatus = quarantined Medium Wazuh XML
ownCloud possible malicious request. Medium Wazuh XML
Simple shell.php command execution. Medium Wazuh XML
The browser has received an illegal datagram from a remote computer Medium Wazuh XML
The value for the parameter to the browser service was illegal Medium Wazuh XML

+ 8 more from Wazuh Core Ruleset → showing the 10 highest-severity

splunk/security_content

12 rules
Detection Severity Format
Cisco Secure Firewall - Binary File Type Download Undefined SPL
Cisco Secure Firewall - Blocked Connection Undefined SPL
Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt Undefined SPL
Cisco Secure Firewall - High Priority Intrusion Classification Undefined SPL
Cisco Secure Firewall - Malware File Downloaded Undefined SPL
Cisco Secure Firewall - Possibly Compromised Host Undefined SPL
Cisco Secure Firewall - Repeated Blocked Connections Undefined SPL
Detect Windows DNS SIGRed via Splunk Stream Undefined SPL
Detect Windows DNS SIGRed via Zeek Undefined SPL
Sunburst Correlation DLL and Network Event Undefined SPL

+ 2 more from splunk/security_content → showing the 10 highest-severity

Azure/Azure-Sentinel

6 rules
Detection Severity Format
Application Gateway WAF - XSS Detection High KQL
Prestige ransomware IOCs Oct 2022 High KQL
Vulnerable Machines related to OMIGOD CVE-2021-38647 High KQL
Malformed user agent Medium KQL
PE file dropped in Color Profile Folder Medium KQL
Suspicious Tomcat Confluence Process Launch Undefined KQL

socfortress/Wazuh-Rules

3 rules
Detection Severity Format
Audit CVE Event Critical Wazuh XML
Sysmon - Event 1: Process creation · win.eventdata.originalFileName = msdt\.exe, win.eventdata.commandLine = ms-msdt:(/|-)id.*(PCWDiagnostic|IT_RebrowseForFile|IT_Launc… Critical Wazuh XML
Sysmon - Event 1: Process creation · win.eventdata.parentImage = winword\.exe$|excel\.exe$|powerpnt\.exe$|outlook\.exe$|msac… High Wazuh XML

chronicle/detection-rules

2 rules
Detection Severity Format
antivirus_exploitation_framework_detection Undefined YARA-L
possible_flash_0day_execute_embedded_in_word_document_sysmon Undefined YARA-L

panther-labs/panther-analysis

2 rules
Detection Severity Format
Databricks Install Library on All Clusters Medium Panther Python
AWS SSM Distributed Command Informational Panther Python

Emerging Threats Open

1 rule
Detection Severity Format
ET MALWARE AsyncRAT Installer Payload Request Critical Suricata

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.