Cross-source coverage
T1203 / ATT&CK
Exploitation for Client Execution
129 rules · 126 families across 10 sources.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.
Several types exist:
Browser-based Exploitation
Web browsers are a common target through Drive-by Compromise and Spearphishing Link. Endpoint systems may be compromised through normal web browsing or from certain users being targeted by links in spearphishing emails to adversary controlled sites used to exploit the web browser. These often do not require an action by the user for the exploit to be executed.
Office Applications
Common office and productivity applications such as Microsoft Office are also targeted through Phishing. Malicious files will be transmitted directly as attachments or through links to download them. These require the user to open the document or file for the exploit to run.
Common Third-party Applications
Other applications that are commonly seen or are part of the software deployed in a target network may also be used for exploitation. Applications such as Adobe Reader and Flash, which are common in enterprise environments, have been routinely targeted by adversaries attempting to gain access to systems. Depending on the software and nature of the vulnerability, some may be exploited in the browser or require the user to open a file. For instance, some Flash exploits have been delivered as objects within Microsoft Office documents.
- Tactics
- Execution
- Platforms
- Linux · macOS · Windows
- Telemetry
-
WinEventLog:ApplicationWinEventLog:Sysmonlinux:syslogauditd:SYSCALLNetFlow:Flowmacos:unifiedlogfs:fseventsmacos:osqueryNSM:Connections
How MITRE says to detect it DET0287
Exploitation for Client Execution – cross-platform behavior chain (browser/Office/3rd-party apps)
Windows Analytic 0797
Cause→effect chain: (1) A client app (browser, Office, PDF/Flash/reader) experiences a crash/abnormal exit or loads from an unusual location, then (2) drops or modifies a file in user-writable paths, and/or (3) spawns an unexpected child (e.g., powershell/cmd/mshta/rundll32/wscript/installer), and (4) establishes outbound C2-like connections shortly after. Correlate application logs, file writes, process lineage, and network egress within a short window.
WinEventLog:ApplicationEventCode=1000WinEventLog:SysmonEventCode=11WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=3, 22
Linux Analytic 0798
Cause→effect chain: (1) Browser/Office/reader process logs crash/segfault or abnormal sandbox message, (2) new executable/script/write occurs in $HOME (Downloads, ~/.cache, /tmp), (3) unexpected child like curl/wget/bash/python opens network connections soon after.
linux:syslogbrowser/office crash, segfault, abnormal terminationauditd:SYSCALLopenauditd:SYSCALLcreatauditd:SYSCALLrename,chmodauditd:SYSCALLexecveNetFlow:Flownew outbound connections from exploited process tree
macOS Analytic 0799
Cause→effect chain: (1) App crash/abnormal termination in unified logs for Safari/Chrome/Office/Preview, (2) new files/scripts in ~/Library, ~/Downloads, /private/var/folders/*, (3) unexpected child (osascript, zsh, bash, curl) spawned by those apps, (4) new outbound connections.
macos:unifiedlogprocess crash, abort, code signing violationsfs:fseventscreate/write/rename under user-writable pathsmacos:osqueryexecNSM:Connectionsnew connections from exploited lineage
SigmaHQ/sigma
35 rules| Detection | Severity | Format |
|---|---|---|
| Antivirus - APT Malware Signature | Critical | Sigma |
| Antivirus - Exploitation Framework Signature | Critical | Sigma |
| Antivirus - Remote Access Tools Signature | Critical | Sigma |
| Audit CVE Event | Critical | Sigma |
| CVE-2021-31979 CVE-2021-33771 Exploits | Critical | Sigma |
| CVE-2021-31979 CVE-2021-33771 Exploits by Sourgum | Critical | Sigma |
| Droppers Exploiting CVE-2017-11882 | Critical | Sigma |
| Exploit for CVE-2017-8759 | Critical | Sigma |
| CVE-2021-26858 Exchange Exploitation | High | Sigma |
| CVE-2023-38331 Exploitation Attempt - Suspicious WinRAR Child Process | High | Sigma |
+ 25 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
29 rules| Detection | Severity | Format |
|---|---|---|
| Cupsd or Foomatic-rip Shell Execution | High | Elastic TOML |
| Execution of File Written or Modified by Microsoft Office | High | Elastic TOML |
| Exploit - Detected - Elastic Endgame | High | Elastic TOML |
| Multiple DHCP Servers Responding to the Same Transaction | High | Elastic TOML |
| Network Connection by Cups or Foomatic-rip Child | High | Elastic TOML |
| Potential CVE-2025-33053 Exploitation | High | Elastic TOML |
| Potential Foxmail Exploitation | High | Elastic TOML |
| Potential Git CVE-2025-48384 Exploitation | High | Elastic TOML |
| Potential JAVA/JNDI Exploitation Attempt | High | Elastic TOML |
| Potential Notepad Markdown RCE Exploitation | High | Elastic TOML |
+ 19 more from elastic/detection-rules → showing the 10 highest-severity
elastic/protections-artifacts
21 rules| Detection | Severity | Format |
|---|---|---|
| Execution from a Remote Working Directory | Undefined | Elastic TOML |
| Execution of File Written or Modified by Microsoft Equation Editor | Undefined | Elastic TOML |
| Microsoft Equation Editor Child Process | Undefined | Elastic TOML |
| Potential Browser Exploit via Fake RPC Messages | Undefined | Elastic TOML |
| Potential CVE-2024-21412 Exploitation | Undefined | Elastic TOML |
| Potential CVE-2025-33053 Exploitation | Undefined | Elastic TOML |
| Potential Execution via Archive Exploit | Undefined | Elastic TOML |
| Potential Execution via Foxmail Exploitation | Undefined | Elastic TOML |
| Potential Execution via WinRAR Exploitation | Undefined | Elastic TOML |
| Potential Git CVE-2025-48384 Exploitation | Undefined | Elastic TOML |
+ 11 more from elastic/protections-artifacts → showing the 10 highest-severity
Wazuh Core Ruleset
18 rules| Detection | Severity | Format |
|---|---|---|
| of an user. | Critical | Wazuh XML |
| The browser driver has discarded too many mailslot messages | High | Wazuh XML |
| The browser driver has received too many illegal datagrams from the remote computer | High | Wazuh XML |
| VirusTotal: Alert - - engines detected this file · virustotal.malicious = 1 | High | Wazuh XML |
| Auditd: File or a directory access ended abnormally. | Medium | Wazuh XML |
| Cylance: File is quarantined. · cylance_events.eventstatus = quarantined | Medium | Wazuh XML |
| ownCloud possible malicious request. | Medium | Wazuh XML |
| Simple shell.php command execution. | Medium | Wazuh XML |
| The browser has received an illegal datagram from a remote computer | Medium | Wazuh XML |
| The value for the parameter to the browser service was illegal | Medium | Wazuh XML |
+ 8 more from Wazuh Core Ruleset → showing the 10 highest-severity
splunk/security_content
12 rules| Detection | Severity | Format |
|---|---|---|
| Cisco Secure Firewall - Binary File Type Download | Undefined | SPL |
| Cisco Secure Firewall - Blocked Connection | Undefined | SPL |
| Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt | Undefined | SPL |
| Cisco Secure Firewall - High Priority Intrusion Classification | Undefined | SPL |
| Cisco Secure Firewall - Malware File Downloaded | Undefined | SPL |
| Cisco Secure Firewall - Possibly Compromised Host | Undefined | SPL |
| Cisco Secure Firewall - Repeated Blocked Connections | Undefined | SPL |
| Detect Windows DNS SIGRed via Splunk Stream | Undefined | SPL |
| Detect Windows DNS SIGRed via Zeek | Undefined | SPL |
| Sunburst Correlation DLL and Network Event | Undefined | SPL |
+ 2 more from splunk/security_content → showing the 10 highest-severity
Azure/Azure-Sentinel
6 rules| Detection | Severity | Format |
|---|---|---|
| Application Gateway WAF - XSS Detection | High | KQL |
| Prestige ransomware IOCs Oct 2022 | High | KQL |
| Vulnerable Machines related to OMIGOD CVE-2021-38647 | High | KQL |
| Malformed user agent | Medium | KQL |
| PE file dropped in Color Profile Folder | Medium | KQL |
| Suspicious Tomcat Confluence Process Launch | Undefined | KQL |
socfortress/Wazuh-Rules
3 rules| Detection | Severity | Format |
|---|---|---|
| Audit CVE Event | Critical | Wazuh XML |
| Sysmon - Event 1: Process creation · win.eventdata.originalFileName = msdt\.exe, win.eventdata.commandLine = ms-msdt:(/|-)id.*(PCWDiagnostic|IT_RebrowseForFile|IT_Launc… | Critical | Wazuh XML |
| Sysmon - Event 1: Process creation · win.eventdata.parentImage = winword\.exe$|excel\.exe$|powerpnt\.exe$|outlook\.exe$|msac… | High | Wazuh XML |
chronicle/detection-rules
2 rules| Detection | Severity | Format |
|---|---|---|
| antivirus_exploitation_framework_detection | Undefined | YARA-L |
| possible_flash_0day_execute_embedded_in_word_document_sysmon | Undefined | YARA-L |
panther-labs/panther-analysis
2 rules| Detection | Severity | Format |
|---|---|---|
| Databricks Install Library on All Clusters | Medium | Panther Python |
| AWS SSM Distributed Command | Informational | Panther Python |
Emerging Threats Open
1 rule| Detection | Severity | Format |
|---|---|---|
| ET MALWARE AsyncRAT Installer Payload Request | Critical | Suricata |