{"id":"T1203","name":"Exploitation for Client Execution","url":"https://attack.mitre.org/techniques/T1203","tactics":["execution"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0287","stix_id":"x-mitre-detection-strategy--1894c2d7-ce4f-4cfd-8644-decb1e14f0c5","name":"Exploitation for Client Execution – cross-platform behavior chain (browser/Office/3rd-party apps)","url":"https://attack.mitre.org/detectionstrategies/DET0287","analytics":[{"id":"AN0797","stix_id":"x-mitre-analytic--065f2c96-6903-4cd1-a737-99ecf1fdc73e","name":"Analytic 0797","description":"Cause→effect chain: (1) A client app (browser, Office, PDF/Flash/reader) experiences a crash/abnormal exit or loads from an unusual location, then (2) drops or modifies a file in user-writable paths, and/or (3) spawns an unexpected child (e.g., powershell/cmd/mshta/rundll32/wscript/installer), and (4) establishes outbound C2-like connections shortly after. Correlate application logs, file writes, process lineage, and network egress within a short window.","url":"https://attack.mitre.org/detectionstrategies/DET0287#AN0797","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Application","channel":"EventCode=1000","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"wineventlog-application"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlation window (e.g., 15m) between crash/write/child/network."},{"field":"HighRiskChildren","description":"List of child processes that should rarely spawn from Office/browsers (powershell.exe, cmd.exe, wscript.exe, mshta.exe, rundll32.exe, regsvr32.exe, msiexec.exe, curl.exe)."},{"field":"UserPaths","description":"Writable paths to watch (Downloads, %TEMP%, %APPDATA%, OneDrive, Office startup folders)."},{"field":"AllowedPlugins","description":"Known add-ins/extensions and updater binaries to reduce noise."},{"field":"EgressAllowlist","description":"Known update/CDN domains and proxy egress CIDRs for suppression."}],"live":true,"detection_strategies":["DET0287"],"techniques":["T1203"]},{"id":"AN0798","stix_id":"x-mitre-analytic--b3b58ac5-6b60-4c34-9842-46f5ee517bcb","name":"Analytic 0798","description":"Cause→effect chain: (1) Browser/Office/reader process logs crash/segfault or abnormal sandbox message, (2) new executable/script/write occurs in $HOME (Downloads, ~/.cache, /tmp), (3) unexpected child like curl/wget/bash/python opens network connections soon after.","url":"https://attack.mitre.org/detectionstrategies/DET0287#AN0798","platforms":["Linux"],"log_source_references":[{"name":"linux:syslog","channel":"browser/office crash, segfault, abnormal termination","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"linux-syslog"},{"name":"auditd:SYSCALL","channel":"open","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"creat","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"rename,chmod","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NetFlow:Flow","channel":"new outbound connections from exploited process tree","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"netflow-flow"}],"mutable_elements":[{"field":"TimeWindow","description":"5–20m correlation window."},{"field":"UserPaths","description":"HOME write targets: ~/Downloads, ~/.config/autostart, ~/.local/share, /tmp."},{"field":"HighRiskChildren","description":"bash, sh, python, perl, node, curl, wget, socat, openssl, xxd."},{"field":"PackageUpdaters","description":"Allow-list common updaters (snap, flatpak, packagekit) to reduce FP."}],"live":true,"detection_strategies":["DET0287"],"techniques":["T1203"]},{"id":"AN0799","stix_id":"x-mitre-analytic--4aaf0a98-c6a9-4b30-a9d9-3a014473bd0e","name":"Analytic 0799","description":"Cause→effect chain: (1) App crash/abnormal termination in unified logs for Safari/Chrome/Office/Preview, (2) new files/scripts in ~/Library, ~/Downloads, /private/var/folders/*, (3) unexpected child (osascript, zsh, bash, curl) spawned by those apps, (4) new outbound connections.","url":"https://attack.mitre.org/detectionstrategies/DET0287#AN0799","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process crash, abort, code signing violations","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"},{"name":"fs:fsevents","channel":"create/write/rename under user-writable paths","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"fs-fsevents"},{"name":"macos:osquery","channel":"exec","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"},{"name":"NSM:Connections","channel":"new connections from exploited lineage","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-connections"}],"mutable_elements":[{"field":"TimeWindow","description":"10–30m correlation window."},{"field":"HighRiskChildren","description":"osascript, bash, zsh, curl, python, pbpaste/pbcopy, open -a Terminal."},{"field":"UserPaths","description":"~/Library/LaunchAgents, ~/Library/Containers/*/Data, /private/var/folders/*."},{"field":"QuarantineBypass","description":"Flag files with missing com.apple.quarantine extended attribute when sourced from internet."}],"live":true,"detection_strategies":["DET0287"],"techniques":["T1203"]}],"live":true,"version":"1.0","techniques":["T1203"]}],"sigma_rules":[{"id":"00d0b5ab-1f55-4120-8e83-487c0a7baf19","title":"Download From Suspicious TLD - Blacklist","author":"Florian Roth (Nextron Systems)","status":"test","level":"low","date":"2017-11-07","modified":"2023-05-18","description":"Detects download of certain file types from hosts in suspicious TLDs","references":["https://www.symantec.com/connect/blogs/shady-tld-research-gdn-and-our-2016-wrap","https://promos.mcafee.com/en-US/PDF/MTMW_Report.pdf","https://www.spamhaus.org/statistics/tlds/","https://krebsonsecurity.com/2018/06/bad-men-at-work-please-dont-click/"],"logsource":{"category":"proxy"},"tags":["attack.initial-access","attack.t1566","attack.execution","attack.t1203","attack.t1204.002"],"path":"rules/web/proxy_generic/proxy_download_susp_tlds_blacklist.yml","techniques":["T1566","T1203","T1204.002"],"cves":[]},{"id":"023394c4-29d5-46ab-92b8-6a534c6f447b","title":"Suspicious HWP Sub Processes","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-10-24","modified":"2021-11-27","description":"Detects suspicious Hangul Word Processor (Hanword) sub processes that could indicate an exploitation","references":["https://www.securitynewspaper.com/2016/11/23/technical-teardown-exploit-malware-hwp-files/","https://www.hybrid-analysis.com/search?query=context:74940dcc5b38f9f9b1a0fea760d344735d7d91b610e6d5bd34533dd0153402c5&from_sample=5db135000388385a7644131f&block_redirect=1","https://twitter.com/cyberwar_15/status/1187287262054076416","https://blog.alyac.co.kr/1901","https://en.wikipedia.org/wiki/Hangul_(word_processor)"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.t1566.001","attack.execution","attack.t1203","attack.t1059.003","attack.g0032"],"path":"rules/windows/process_creation/proc_creation_win_hwp_exploits.yml","techniques":["T1566.001","T1203","T1059.003"],"cves":[]},{"id":"0250638a-2b28-4541-86fc-ea4c558fa0c6","title":"Suspicious Browser Child Process - MacOS","author":"Sohan G (D4rkCiph3r)","status":"test","level":"medium","date":"2023-04-05","modified":null,"description":"Detects suspicious child processes spawned from browsers. This could be a result of a potential web browser exploitation.","references":["https://fr.slideshare.net/codeblue_jp/cb19-recent-apt-attack-on-crypto-exchange-employees-by-heungsoo-kang","https://github.com/elastic/detection-rules/blob/4312d8c9583be524578a14fe6295c3370b9a9307/rules/macos/execution_initial_access_suspicious_browser_childproc.toml"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.initial-access","attack.execution","attack.t1189","attack.t1203","attack.t1059"],"path":"rules/macos/process_creation/proc_creation_macos_susp_browser_child_process.yml","techniques":["T1189","T1203","T1059"],"cves":[]},{"id":"101a1877-2cf4-474d-abfd-7f6ac4788d1a","title":"Antivirus - APT Malware Signature","author":"Arnim Rupp (Nextron Systems)","status":"experimental","level":"critical","date":"2026-06-15","modified":null,"description":"Detects a highly relevant Antivirus alert that reports APT malware.\nThis event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.\n","references":["https://www.nextron-systems.com/?s=antivirus"],"logsource":{"category":"antivirus"},"tags":["attack.execution","attack.t1203","attack.command-and-control","attack.t1219.002"],"path":"rules/category/antivirus/av_advanced_persistent_threat.yml","techniques":["T1203","T1219.002"],"cves":[]},{"id":"146aace8-9bd6-42ba-be7a-0070d8027b76","title":"Potentially Suspicious Child Process Of WinRAR.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-08-31","modified":null,"description":"Detects potentially suspicious child processes of WinRAR.exe.","references":["https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/","https://github.com/knight0x07/WinRAR-Code-Execution-Vulnerability-CVE-2023-38831/blob/26ab6c40b6d2c09bb4fc60feaa4a3a90cfd20c23/Part-1-Overview.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1203"],"path":"rules/windows/process_creation/proc_creation_win_winrar_susp_child_process.yml","techniques":["T1203"],"cves":[]},{"id":"21541900-27a9-4454-9c4c-3f0a4240344a","title":"OMIGOD SCX RunAsProvider ExecuteShellCommand","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC","status":"test","level":"high","date":"2021-10-15","modified":"2022-10-05","description":"Rule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell.\nSCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including\nMicrosoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.\n","references":["https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure","https://github.com/Azure/Azure-Sentinel/pull/3059"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.privilege-escalation","attack.initial-access","attack.execution","attack.t1068","attack.t1190","attack.t1203"],"path":"rules/linux/process_creation/proc_creation_lnx_omigod_scx_runasprovider_executeshellcommand.yml","techniques":["T1068","T1190","T1203"],"cves":[]},{"id":"238527ad-3c2c-4e4f-a1f6-92fd63adb864","title":"Antivirus - Exploitation Framework Signature","author":"Florian Roth (Nextron Systems), Arnim Rupp","status":"stable","level":"critical","date":"2018-09-09","modified":"2026-06-15","description":"Detects a highly relevant Antivirus alert that reports an exploitation framework.\nThis event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.\n","references":["https://www.nextron-systems.com/?s=antivirus","https://www.virustotal.com/gui/file/925b0b28472d4d79b4bf92050e38cc2b8f722691c713fc28743ac38551bc3797","https://www.virustotal.com/gui/file/8f8daabe1c8ceb5710949283818e16c4aa8059bf2ce345e2f2c90b8692978424","https://www.virustotal.com/gui/file/d9669f7e3eb3a9cdf6a750eeb2ba303b5ae148a43e36546896f1d1801e912466"],"logsource":{"category":"antivirus"},"tags":["attack.execution","attack.t1203","attack.command-and-control","attack.t1219.002"],"path":"rules/category/antivirus/av_exploitation_framework.yml","techniques":["T1203","T1219.002"],"cves":[]},{"id":"297241f3-8108-4b3a-8c15-2dda9f844594","title":"Suspicious Invocation of Shell via Rsync","author":"Florian Roth","status":"experimental","level":"high","date":"2025-01-18","modified":null,"description":"Detects the execution of a shell as sub process of \"rsync\" without the expected command line flag \"-e\" being used, which could be an indication of exploitation as described in CVE-2024-12084. This behavior is commonly associated with attempts to execute arbitrary commands or escalate privileges, potentially leading to unauthorized access or further exploitation.\n","references":["https://sysdig.com/blog/detecting-and-mitigating-cve-2024-12084-rsync-remote-code-execution/","https://gist.github.com/Neo23x0/a20436375a1e26524931dd8ea1a3af10"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.execution","attack.t1059","attack.t1203"],"path":"rules/linux/process_creation/proc_creation_lnx_rsync_shell_spawn.yml","techniques":["T1059","T1203"],"cves":[]},{"id":"32b5db62-cb5f-4266-9639-0fa48376ac00","title":"CVE-2021-31979 CVE-2021-33771 Exploits","author":"Sittikorn S, frack113","status":"test","level":"critical","date":"2021-07-16","modified":"2023-08-17","description":"Detects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum","references":["https://www.microsoft.com/security/blog/2021/07/15/protecting-customers-from-a-private-sector-offensive-actor-using-0-day-exploits-and-devilstongue-malware/","https://citizenlab.ca/2021/07/hooking-candiru-another-mercenary-spyware-vendor-comes-into-focus/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.initial-access","attack.execution","attack.credential-access","attack.t1566","attack.t1203","cve.2021-33771","cve.2021-31979","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-33771/registry_set_cve_2021_31979_cve_2021_33771_exploits.yml","techniques":["T1566","T1203"],"cves":["CVE-2021-33771","CVE-2021-31979"]},{"id":"3c21219b-49b5-4268-bce6-c914ed50f09c","title":"Dfsvc.EXE Network Connection To Non-Local IPs","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-06-12","modified":"2024-03-12","description":"Detects network connections from \"dfsvc.exe\" used to handled ClickOnce applications to non-local IPs","references":["https://posts.specterops.io/less-smartscreen-more-caffeine-ab-using-clickonce-for-trusted-code-execution-1446ea8051c5"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.execution","attack.t1203","detection.threat-hunting"],"path":"rules-threat-hunting/windows/network_connection/net_connection_win_dfsvc_non_local_ip.yml","techniques":["T1203"],"cves":[]},{"id":"41956f7c-7a6b-46d6-b6bb-da6eb2e83fbe","title":"Potential Exploitation of CVE-2025-4427/4428 Ivanti EPMM Pre-Auth RCE","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-05-20","modified":null,"description":"Detects potential exploitation of a chained vulnerability attack targeting Ivanti EPMM 12.5.0.0.\nCVE-2025-4427 allows unauthenticated access to protected API endpoints via an authentication bypass,\nwhich can then be leveraged to trigger CVE-2025-4428 — a remote code execution vulnerability through\ntemplate injection. This sequence enables unauthenticated remote code execution, significantly increasing\nthe impact of exploitation.\n","references":["https://labs.watchtowr.com/expression-payloads-meet-mayhem-cve-2025-4427-and-cve-2025-4428/?123"],"logsource":{"category":"webserver"},"tags":["attack.initial-access","attack.t1190","attack.execution","attack.t1203","cve.2025-4427","cve.2025-4428","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-4427/web_invanti_epmm_cve_2025_4427_and_cve_2025_4428.yml","techniques":["T1190","T1203"],"cves":["CVE-2025-4427","CVE-2025-4428"]},{"id":"43259cc4-1b80-4931-bd98-baea01afc196","title":"Exploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Process","author":"Huntress Labs, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-10-31","modified":null,"description":"Detects the creation of command-line interpreters (cmd.exe, powershell.exe) as child processes of Windows Server Update Services (WSUS) related process wsusservice.exe.\nThis behavior is a key indicator of exploitation for the critical remote code execution vulnerability such as CVE-2025-59287, where attackers spawn shells to conduct reconnaissance and further post-exploitation activities.\n","references":["https://unit42.paloaltonetworks.com/microsoft-cve-2025-59287/","https://www.huntress.com/blog/exploitation-of-windows-server-update-services-remote-code-execution-vulnerability","https://hawktrace.com/blog/CVE-2025-59287-UNAUTH"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.initial-access","attack.t1190","attack.t1203","cve.2025-59287","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-59287/proc_creation_win_exploit_cve_2025_59287.yml","techniques":["T1190","T1203"],"cves":["CVE-2025-59287"]},{"id":"48d91a3a-2363-43ba-a456-ca71ac3da5c2","title":"Audit CVE Event","author":"Florian Roth (Nextron Systems), Zach Mathis","status":"test","level":"critical","date":"2020-01-15","modified":"2022-10-22","description":"Detects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited.\nMS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability.\nUnfortunately, that is about the only instance of CVEs being written to this log.\n","references":["https://twitter.com/VM_vivisector/status/1217190929330655232","https://twitter.com/DidierStevens/status/1217533958096924676","https://twitter.com/FlemmingRiis/status/1217147415482060800","https://www.youtube.com/watch?v=ebmW42YYveI","https://nullsec.us/windows-event-log-audit-cve/"],"logsource":{"product":"windows","service":"application"},"tags":["attack.execution","attack.stealth","attack.t1203","attack.privilege-escalation","attack.t1068","attack.t1211","attack.credential-access","attack.t1212","attack.lateral-movement","attack.t1210","attack.impact","attack.t1499.004"],"path":"rules/windows/builtin/application/microsoft-windows_audit_cve/win_audit_cve.yml","techniques":["T1203","T1068","T1211","T1212","T1210","T1499.004"],"cves":[]},{"id":"4c5fba4a-9ef6-4f16-823d-606246054741","title":"Dfsvc.EXE Initiated Network Connection Over Uncommon Port","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-06-12","modified":"2024-01-31","description":"Detects an initiated network connection over uncommon ports from \"dfsvc.exe\". A utility used to handled ClickOnce applications.","references":["https://posts.specterops.io/less-smartscreen-more-caffeine-ab-using-clickonce-for-trusted-code-execution-1446ea8051c5"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.execution","attack.t1203","detection.threat-hunting"],"path":"rules-threat-hunting/windows/network_connection/net_connection_win_dfsvc_uncommon_ports.yml","techniques":["T1203"],"cves":[]},{"id":"5299fadf-f228-4526-8274-251db1960be9","title":"Shai-Hulud Malicious Bun Execution","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-11-25","modified":null,"description":"Detects the execution of `bun_environment.js` via the Bun runtime, a behavior associated with the Shai-Hulud \"Second Coming\" NPM supply chain attack.\nThe malware uses a `setup_bun.js` script to install the Bun runtime if not present, and then executes the malicious `bun_environment.js` payload.\n","references":["https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains","https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack","https://github.com/asyncapi/cli/blob/2efa4dff59bc3d3cecdf897ccf178f99b115d63d/setup_bun.js","https://semgrep.dev/blog/2025/digging-for-secrets-sha1-hulud-the-second-coming-of-the-npm-worm/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1195.002","attack.t1203","attack.execution","attack.initial-access","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Malware/Shai-Hulud/proc_creation_win_mal_shai_hulud_malicious_node_bun_execution.yml","techniques":["T1195.002","T1203"],"cves":[]},{"id":"678eb5f4-8597-4be6-8be7-905e4234b53a","title":"Droppers Exploiting CVE-2017-11882","author":"Florian Roth (Nextron Systems)","status":"stable","level":"critical","date":"2017-11-23","modified":"2021-11-27","description":"Detects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe","references":["https://www.hybrid-analysis.com/sample/2a4ae284c76f868fc51d3bb65da8caa6efacb707f265b25c30f34250b76b7507?environmentId=100","https://www.linkedin.com/pulse/exploit-available-dangerous-ms-office-rce-vuln-called-thebenygreen-","https://github.com/embedi/CVE-2017-11882"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1203","attack.t1204.002","attack.initial-access","attack.t1566.001","cve.2017-11882","detection.emerging-threats"],"path":"rules-emerging-threats/2017/Exploits/CVE-2017-11882/proc_creation_win_exploit_cve_2017_11882.yml","techniques":["T1203","T1204.002","T1566.001"],"cves":["CVE-2017-11882"]},{"id":"6eea1bf6-f8d2-488a-a742-e6ef6c1b67db","title":"OMIGOD SCX RunAsProvider ExecuteScript","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC","status":"test","level":"high","date":"2021-10-15","modified":"2022-10-05","description":"Rule to detect the use of the SCX RunAsProvider ExecuteScript to execute any UNIX/Linux script using the /bin/sh shell.\nScript being executed gets created as a temp file in /tmp folder with a scx* prefix.\nThen it is invoked from the following directory /etc/opt/microsoft/scx/conf/tmpdir/.\nThe file in that directory has the same prefix scx*. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including\nMicrosoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.\n","references":["https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure","https://github.com/Azure/Azure-Sentinel/pull/3059"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.privilege-escalation","attack.initial-access","attack.execution","attack.t1068","attack.t1190","attack.t1203"],"path":"rules/linux/process_creation/proc_creation_lnx_omigod_scx_runasprovider_executescript.yml","techniques":["T1068","T1190","T1203"],"cves":[]},{"id":"75e33ce3-ae32-4dcc-9aa8-a2a3029d6f84","title":"Office Application Initiated Network Connection To Non-Local IP","author":"Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2021-11-10","modified":"2025-10-17","description":"Detects an office application (Word, Excel, PowerPoint)  that initiate a network connection to a non-private IP addresses.\nThis rule aims to detect traffic similar to one seen exploited in CVE-2021-42292.\nThis rule will require an initial baseline and tuning that is specific to your organization.\n","references":["https://corelight.com/blog/detecting-cve-2021-42292","https://learn.microsoft.com/de-de/microsoft-365/enterprise/urls-and-ip-address-ranges?view=o365-worldwide"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.execution","attack.t1203"],"path":"rules/windows/network_connection/net_connection_win_office_outbound_non_local_ip.yml","techniques":["T1203"],"cves":[]},{"id":"864403a1-36c9-40a2-a982-4c9a45f7d833","title":"Exploit for CVE-2017-0261","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2018-02-22","modified":"2021-11-27","description":"Detects Winword starting uncommon sub process FLTLDR.exe as used in exploits for CVE-2017-0261 and CVE-2017-0262","references":["https://www.fireeye.com/blog/threat-research/2017/05/eps-processing-zero-days.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1203","attack.t1204.002","attack.initial-access","attack.t1566.001","cve.2017-0261","detection.emerging-threats"],"path":"rules-emerging-threats/2017/Exploits/CVE-2017-0261/proc_creation_win_exploit_cve_2017_0261.yml","techniques":["T1203","T1204.002","T1566.001"],"cves":["CVE-2017-0261"]},{"id":"8e95e73e-ba02-4a87-b4d7-0929b8053038","title":"Suspicious ArcSOC.exe Child Process","author":"Micah Babinski","status":"experimental","level":"high","date":"2025-11-25","modified":null,"description":"Detects script interpreters, command-line tools, and similar suspicious child processes of ArcSOC.exe.\nArcSOC.exe is the process name which hosts ArcGIS Server REST services. If an attacker compromises an ArcGIS\nServer system and uploads a malicious Server Object Extension (SOE), they can send crafted requests to the corresponding\nservice endpoint and remotely execute code from the ArcSOC.exe process.\n","references":["https://reliaquest.com/blog/threat-spotlight-inside-flax-typhoons-arcgis-compromise/","https://enterprise.arcgis.com/en/server/12.0/administer/windows/inside-an-arcgis-server-site.htm"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059","attack.t1203"],"path":"rules/windows/process_creation/proc_creation_win_arcsoc_susp_child_process.yml","techniques":["T1059","T1203"],"cves":[]},{"id":"8f88e3f6-2a49-48f5-a5c4-2f7eedf78710","title":"Java Running with Remote Debugging","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2019-01-16","modified":"2023-02-01","description":"Detects a JAVA process running with remote debugging allowing more than just localhost to connect","references":["https://dzone.com/articles/remote-debugging-java-applications-with-jdwp"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1203","attack.execution"],"path":"rules/windows/process_creation/proc_creation_win_java_remote_debugging.yml","techniques":["T1203"],"cves":[]},{"id":"97233998-3838-4581-88c6-f1d19d3993fb","title":"Antivirus - Remote Access Tools Signature","author":"Arnim Rupp (Nextron Systems)","status":"experimental","level":"critical","date":"2026-06-15","modified":null,"description":"Detects a highly relevant Antivirus alert that reports a remote access tool.\nThis event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.\n","references":["https://www.nextron-systems.com/?s=antivirus","https://www.virustotal.com/gui/file/d9669f7e3eb3a9cdf6a750eeb2ba303b5ae148a43e36546896f1d1801e912466"],"logsource":{"category":"antivirus"},"tags":["attack.execution","attack.t1203","attack.command-and-control","attack.t1219.002"],"path":"rules/category/antivirus/av_remote_access_toolkit.yml","techniques":["T1203","T1219.002"],"cves":[]},{"id":"a2d9e2f3-0f43-4c7a-bcd9-9acfc0d723aa","title":"Suspicious Download and Execute Pattern via Curl/Wget","author":"Aayush Gupta","status":"experimental","level":"high","date":"2025-06-17","modified":null,"description":"Detects suspicious use of command-line tools such as curl or wget to download remote\ncontent - particularly scripts - into temporary directories (e.g., /dev/shm, /tmp), followed by\nimmediate execution, indicating potential malicious activity. This pattern is commonly used\nby malicious scripts, stagers, or downloaders in fileless or multi-stage Linux attacks.\n","references":["https://gtfobins.github.io/gtfobins/wget/","https://gtfobins.github.io/gtfobins/curl/"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.execution","attack.t1059.004","attack.t1203"],"path":"rules/linux/process_creation/proc_creation_lnx_curl_wget_exec_tmp.yml","techniques":["T1059.004","T1203"],"cves":[]},{"id":"a66bc059-c370-472c-a0d7-f8fd1bf9d583","title":"Network Connection Initiated By Eqnedt32.EXE","author":"Max Altgelt (Nextron Systems)","status":"test","level":"high","date":"2022-04-14","modified":"2024-05-31","description":"Detects network connections from the Equation Editor process \"eqnedt32.exe\".","references":["https://twitter.com/forensicitguy/status/1513538712986079238","https://forensicitguy.github.io/xloader-formbook-velvetsweatshop-spreadsheet/","https://news.sophos.com/en-us/2019/07/18/a-new-equation-editor-exploit-goes-commercial-as-maldoc-attacks-using-it-spike/"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.execution","attack.t1203"],"path":"rules/windows/network_connection/net_connection_win_eqnedt.yml","techniques":["T1203"],"cves":[]},{"id":"ab6b1a39-a9ee-4ab4-b075-e83acf6e346b","title":"OMIGOD HTTP No Authentication RCE - CVE-2021-38647","author":"Nate Guagenti (neu5ron)","status":"stable","level":"high","date":"2021-09-20","modified":"2025-11-03","description":"Detects the exploitation of OMIGOD (CVE-2021-38647) which allows remote execute (RCE) commands as root with just a single unauthenticated HTTP request.\nVerify, successful, exploitation by viewing the HTTP client (request) body to see what was passed to the server (using PCAP).\nWithin the client body is where the code execution would occur. Additionally, check the endpoint logs to see if suspicious commands or activity occurred within the timeframe of this HTTP request.\n","references":["https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure","https://twitter.com/neu5ron/status/1438987292971053057?s=20"],"logsource":{"product":"zeek","service":"http"},"tags":["attack.privilege-escalation","attack.initial-access","attack.execution","attack.lateral-movement","attack.t1068","attack.t1190","attack.t1203","attack.t1021.006","attack.t1210","detection.emerging-threats","cve.2021-38647"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-38647/zeek_http_exploit_cve_2021_38647_omigod_no_auth_rce.yml","techniques":["T1068","T1190","T1203","T1021.006","T1210"],"cves":["CVE-2021-38647"]},{"id":"ad7085ac-92e4-4b76-8ce2-276d2c0e68ef","title":"CVE-2021-31979 CVE-2021-33771 Exploits by Sourgum","author":"Sittikorn S","status":"test","level":"critical","date":"2021-07-16","modified":"2022-10-09","description":"Detects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum","references":["https://www.microsoft.com/security/blog/2021/07/15/protecting-customers-from-a-private-sector-offensive-actor-using-0-day-exploits-and-devilstongue-malware/","https://citizenlab.ca/2021/07/hooking-candiru-another-mercenary-spyware-vendor-comes-into-focus/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.initial-access","attack.execution","attack.credential-access","attack.t1566","attack.t1203","cve.2021-33771","cve.2021-31979","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-33771/file_event_win_cve_2021_31979_cve_2021_33771_exploits.yml","techniques":["T1566","T1203"],"cves":["CVE-2021-33771","CVE-2021-31979"]},{"id":"b06335b3-55ac-4b41-937e-16b7f5d57dfd","title":"CVE-2021-26858 Exchange Exploitation","author":"Bhabesh Raj","status":"test","level":"high","date":"2021-03-03","modified":"2022-10-09","description":"Detects possible successful exploitation for vulnerability described in CVE-2021-26858 by looking for\ncreation of non-standard files on disk by Exchange Server’s Unified Messaging service\nwhich could indicate dropping web shells or other malicious content\n","references":["https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.t1203","attack.execution","cve.2021-26858","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-26858/file_event_win_cve_2021_26858_msexchange.yml","techniques":["T1203"],"cves":["CVE-2021-26858"]},{"id":"b5de2919-b74a-4805-91a7-5049accbaefe","title":"Download From Suspicious TLD - Whitelist","author":"Florian Roth (Nextron Systems)","status":"test","level":"low","date":"2017-03-13","modified":"2023-05-18","description":"Detects executable downloads from suspicious remote systems","references":["Internal Research"],"logsource":{"category":"proxy"},"tags":["attack.initial-access","attack.t1566","attack.execution","attack.t1203","attack.t1204.002"],"path":"rules/web/proxy_generic/proxy_download_susp_tlds_whitelist.yml","techniques":["T1566","T1203","T1204.002"],"cves":[]},{"id":"ca5583e9-8f80-46ac-ab91-7f314d13b984","title":"Potentially Suspicious Child Process of KeyScrambler.exe","author":"Swachchhanda Shrawan Poudel","status":"test","level":"medium","date":"2024-05-13","modified":null,"description":"Detects potentially suspicious child processes of KeyScrambler.exe","references":["https://twitter.com/DTCERT/status/1712785421845790799"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.execution","attack.privilege-escalation","attack.stealth","attack.t1203","attack.t1574.001"],"path":"rules/windows/process_creation/proc_creation_win_keyscrambler_susp_child_process.yml","techniques":["T1203","T1574.001"],"cves":[]},{"id":"cd479ccc-d8f0-4c66-ba7d-e06286f3f887","title":"Potential CVE-2021-26857 Exploitation Attempt","author":"Bhabesh Raj","status":"stable","level":"high","date":"2021-03-03","modified":"2023-02-07","description":"Detects possible successful exploitation for vulnerability described in CVE-2021-26857 by looking for | abnormal subprocesses spawning by Exchange Server's Unified Messaging service","references":["https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1203","attack.execution","cve.2021-26857","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-26857/proc_creation_win_exploit_cve_2021_26857_msexchange.yml","techniques":["T1203"],"cves":["CVE-2021-26857"]},{"id":"dcdbc940-0bff-46b2-95f3-2d73f848e33b","title":"Suspicious Spool Service Child Process","author":"Justin C. (@endisphotic), @dreadphones (detection), Thomas Patzke (Sigma rule)","status":"test","level":"high","date":"2021-07-11","modified":"2024-12-01","description":"Detects suspicious print spool service (spoolsv.exe) child processes.","references":["https://github.com/microsoft/Microsoft-365-Defender-Hunting-Queries/blob/efa17a600b43c897b4b7463cc8541daa1987eeb4/Exploits/Print%20Spooler%20RCE/Suspicious%20Spoolsv%20Child%20Process.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1203","attack.privilege-escalation","attack.t1068"],"path":"rules/windows/process_creation/proc_creation_win_spoolsv_susp_child_processes.yml","techniques":["T1203","T1068"],"cves":[]},{"id":"e5f66e87-7d6b-404f-92fe-7aa67814b5cd","title":"Exploitation Activity of CVE-2025-59287 - WSUS Deserialization","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-10-31","modified":null,"description":"Detects cast exceptions in Windows Server Update Services (WSUS) application logs that highly indicate exploitation attempts of CVE-2025-59287, a deserialization vulnerability in WSUS.\n","references":["https://unit42.paloaltonetworks.com/cve-2025-59287/","https://hawktrace.com/blog/CVE-2025-59287-UNAUTH","https://github.com/0xBruno/WSUSploit.NET/tree/e239bce9d6b5f46a346e1e4c4d5e0a2a20d5c639","https://www.huntress.com/blog/exploitation-of-windows-server-update-services-remote-code-execution-vulnerability"],"logsource":{"product":"windows","service":"application"},"tags":["attack.execution","attack.initial-access","attack.t1190","attack.t1203","cve.2025-59287","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-59287/win_wsus_exploit_cve_2025_59287.yml","techniques":["T1190","T1203"],"cves":["CVE-2025-59287"]},{"id":"eb827bbd-670a-4d58-8446-c464d8ac2323","title":"Shai-Hulud Malicious Bun Execution - Linux","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-11-25","modified":null,"description":"Detects the execution of `bun_environment.js` via the Bun runtime, a behavior associated with the Shai-Hulud \"Second Coming\" NPM supply chain attack.\nThe malware uses a `setup_bun.js` script to install the Bun runtime if not present, and then executes the malicious `bun_environment.js` payload.\n","references":["https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains","https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack","https://github.com/asyncapi/cli/blob/2efa4dff59bc3d3cecdf897ccf178f99b115d63d/setup_bun.js"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.t1195.002","attack.t1203","attack.execution","attack.initial-access","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Malware/Shai-Hulud/proc_creation_lnx_mal_shai_hulud_malicious_node_bun_execution.yml","techniques":["T1195.002","T1203"],"cves":[]},{"id":"ec3a3c2f-9bb0-4a9b-8f4b-5ec386544343","title":"CVE-2023-38331 Exploitation Attempt - Suspicious WinRAR Child Process","author":"Nasreddine Bencherchali (Nextron Systems), Andreas Braathen (mnemonic.io)","status":"test","level":"high","date":"2023-08-30","modified":"2024-01-22","description":"Detects exploitation attempt of CVE-2023-38331 (WinRAR before v6.23), where an attacker can leverage WinRAR to execute arbitrary commands and binaries.","references":["https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/","https://github.com/knight0x07/WinRAR-Code-Execution-Vulnerability-CVE-2023-38831/blob/26ab6c40b6d2c09bb4fc60feaa4a3a90cfd20c23/Part-1-Overview.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["detection.emerging-threats","attack.execution","attack.t1203","cve.2023-38331"],"path":"rules-emerging-threats/2023/Exploits/CVE-2023-38831/proc_creation_win_exploit_cve_2023_38831_winrar_child_proc.yml","techniques":["T1203"],"cves":["CVE-2023-38331"]},{"id":"fdd84c68-a1f6-47c9-9477-920584f94905","title":"Exploit for CVE-2017-8759","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2017-09-15","modified":"2021-11-27","description":"Detects Winword starting uncommon sub process csc.exe as used in exploits for CVE-2017-8759","references":["https://www.hybrid-analysis.com/sample/0b4ef455e385b750d9f90749f1467eaf00e46e8d6c2885c260e1b78211a51684?environmentId=100","https://www.reverse.it/sample/0b4ef455e385b750d9f90749f1467eaf00e46e8d6c2885c260e1b78211a51684?environmentId=100"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1203","attack.t1204.002","attack.initial-access","attack.t1566.001","cve.2017-8759","detection.emerging-threats"],"path":"rules-emerging-threats/2017/Exploits/CVE-2017-8759/proc_creation_win_exploit_cve_2017_8759.yml","techniques":["T1203","T1204.002","T1566.001"],"cves":["CVE-2017-8759"]}],"kev_cves":[{"cveID":"CVE-2025-6558","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-6554","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-6543","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-43200","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-24016","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2025-5419","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-27038","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-3935","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-4427","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-42999","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-30397","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-11120","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-3248","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-31201","state":"stale","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-31200","state":"stale","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-30406","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-2783","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-24993","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-43769","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-23748","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-45195","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-26169","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-5274","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-34048","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-49897","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-47565","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-36844","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-21608","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-26369","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-29256","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-23397","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2021-39144","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-41128","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-20703","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-20701","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2015-5119","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2018-4939","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2021-21166","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-21148","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-37975","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-30554","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2021-21206","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2021-27059","state":"mapped","mapping_types":["exploitation_technique"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}