Techniques › T1203
T1203 Exploitation for Client Execution
execution — Linux, macOS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
3
analytics
35
Sigma rules tagged attack.t1203
43
KEV CVEs mapped here
<p>Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.</p><p>Several types exist:</p><p>### Browser-based Exploitation</p><p>Web browsers are a common target through Drive-by Compromise and Spearphishing Link. Endpoint systems may be compromised through normal web browsing or from certain users being targeted by links in spearphishing emails to adversary controlled sites used to exploit the web browser. These often do not require an action by the user for the exploit to be executed.</p><p>### Office Applications</p><p>Common office and productivity applications such as Microsoft Office are also targeted through Phishing. Malicious files will be transmitted directly as attachments or through links to download them. These require the user to open the document or file for the exploit to run.</p><p>### Common Third-party Applications</p><p>Other applications that are commonly seen or are part of the software deployed in a target network may also be used for exploitation. Applications such as Adobe Reader and Flash, which are common in enterprise environments, have been routinely targeted by adversaries attempting to gain access to systems. Depending on the software and nature of the vulnerability, some may be exploited in the browser or require the user to open a file. For instance, some Flash exploits have been delivered as objects within Microsoft Office documents.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2025-6558 | Google Chromium | exploitation technique | Mapped | 2025-07-22 |
| CVE-2025-6554 | Google Chromium V8 | exploitation technique | Mapped | 2025-07-02 |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway | exploitation technique | Mapped | 2025-06-30 |
| CVE-2025-43200 | Apple Multiple Products | exploitation technique | Mapped | 2025-06-16 |
| CVE-2025-24016 | Wazuh Wazuh Server | secondary impact | Mapped | 2025-06-10 |
| CVE-2025-5419 | Google Chromium V8 | exploitation technique | Mapped | 2025-06-05 |
| CVE-2025-27038 | Qualcomm Multiple Chipsets | exploitation technique | Mapped | 2025-06-03 |
| CVE-2025-3935 | ConnectWise ScreenConnect | exploitation technique | Mapped | 2025-06-02 |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) | exploitation technique | Mapped | 2025-05-19 |
| CVE-2025-42999 | SAP NetWeaver | exploitation technique | Mapped | 2025-05-15 |
| CVE-2025-30397 | Microsoft Windows | exploitation technique | Mapped | 2025-05-13 |
| CVE-2024-11120 | GeoVision Multiple Devices | exploitation technique | Mapped | 2025-05-07 |
| CVE-2025-3248 | Langflow Langflow | exploitation technique | Mapped | 2025-05-05 |
| CVE-2025-31201 | Apple Multiple Products | exploitation technique | Stale | 2025-04-17 |
| CVE-2025-31200 | Apple Multiple Products | exploitation technique | Stale | 2025-04-17 |
| CVE-2025-30406 | Gladinet CentreStack | exploitation technique | Mapped | 2025-04-08 |
| CVE-2025-2783 | Google Chromium Mojo | exploitation technique | Mapped | 2025-03-27 |
| CVE-2025-24993 | Microsoft Windows | exploitation technique | Mapped | 2025-03-11 |
| CVE-2022-43769 | Hitachi Vantara Pentaho Business Analytics (BA) Server | exploitation technique | Mapped | 2025-03-03 |
| CVE-2022-23748 | Audinate Dante Discovery | exploitation technique | Mapped | 2025-02-06 |
| CVE-2024-45195 | Apache OFBiz | exploitation technique | Mapped | 2025-02-04 |
| CVE-2024-26169 | Microsoft Windows | exploitation technique | Mapped | 2024-06-13 |
| CVE-2024-5274 | Google Chromium V8 | primary impact | Mapped | 2024-05-28 |
| CVE-2023-34048 | VMware vCenter Server | primary impact | Mapped | 2024-01-22 |
| CVE-2023-49897 | FXC AE1021, AE1021PE | exploitation technique | Mapped | 2023-12-21 |
| CVE-2023-47565 | QNAP VioStor NVR | exploitation technique | Mapped | 2023-12-21 |
| CVE-2023-36844 | Juniper Junos OS | exploitation technique | Mapped | 2023-11-13 |
| CVE-2023-21608 | Adobe Acrobat and Reader | primary impact | Mapped | 2023-10-10 |
| CVE-2023-26369 | Adobe Acrobat and Reader | primary impact | Mapped | 2023-09-14 |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | exploitation technique | Mapped | 2023-07-07 |
| CVE-2023-23397 | Microsoft Office | exploitation technique | Mapped | 2023-03-14 |
| CVE-2021-39144 | XStream XStream | primary impact | Mapped | 2023-03-10 |
| CVE-2022-41128 | Microsoft Windows | primary impact | Mapped | 2022-11-08 |
| CVE-2022-20703 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | exploitation technique | Mapped | 2022-03-03 |
| CVE-2022-20701 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | primary impact | Mapped | 2022-03-03 |
| CVE-2015-5119 | Adobe Flash Player | exploitation technique | Mapped | 2022-03-03 |
| CVE-2018-4939 | Adobe ColdFusion | exploitation technique | Mapped | 2021-11-03 |
| CVE-2021-21166 | Google Chromium | primary impact | Mapped | 2021-11-03 |
| CVE-2021-21148 | Google Chromium V8 | primary impact | Mapped | 2021-11-03 |
| CVE-2021-37975 | Google Chromium V8 | primary impact | Mapped | 2021-11-03 |
| CVE-2021-30554 | Google Chromium WebGL | exploitation technique | Mapped | 2021-11-03 |
| CVE-2021-21206 | Google Chromium Blink | exploitation technique | Mapped | 2021-11-03 |
| CVE-2021-27059 | Microsoft Office | exploitation technique | Mapped | 2021-11-03 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0287 Exploitation for Client Execution – cross-platform behavior chain (browser/Office/3rd-party apps) v1.0
AN0797 WindowsCause→effect chain: (1) A client app (browser, Office, PDF/Flash/reader) experiences a crash/abnormal exit or loads from an unusual location, then (2) drops or modifies a file in user-writable paths, and/or (3) spawns an unexpected child (e.g., powershell/cmd/mshta/rundll32/wscript/installer), and (4) establishes outbound C2-like connections shortly after. Correlate application logs, file writes, process lineage, and network egress within a short window.Tunable:
TimeWindowHighRiskChildrenUserPathsAllowedPluginsEgressAllowlistAN0798 LinuxCause→effect chain: (1) Browser/Office/reader process logs crash/segfault or abnormal sandbox message, (2) new executable/script/write occurs in $HOME (Downloads, ~/.cache, /tmp), (3) unexpected child like curl/wget/bash/python opens network connections soon after.Tunable:TimeWindowUserPathsHighRiskChildrenPackageUpdatersAN0799 macOSCause→effect chain: (1) App crash/abnormal termination in unified logs for Safari/Chrome/Office/Preview, (2) new files/scripts in ~/Library, ~/Downloads, /private/var/folders/*, (3) unexpected child (osascript, zsh, bash, curl) spawned by those apps, (4) new outbound connections.Tunable:TimeWindowHighRiskChildrenUserPathsQuarantineBypass
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1203
Author: Florian Roth (Nextron Systems)
· 2017-11-07 (modified 2023-05-18) · logsource: category=proxy · 00d0b5ab-1f55-4120-8e83-487c0a7baf19
Detects download of certain file types from hosts in suspicious TLDs
Author: Florian Roth (Nextron Systems)
· 2019-10-24 (modified 2021-11-27) · logsource: product=windows category=process_creation · 023394c4-29d5-46ab-92b8-6a534c6f447b
Detects suspicious Hangul Word Processor (Hanword) sub processes that could indicate an exploitation
Author: Sohan G (D4rkCiph3r)
· 2023-04-05 · logsource: product=macos category=process_creation · 0250638a-2b28-4541-86fc-ea4c558fa0c6
Detects suspicious child processes spawned from browsers. This could be a result of a potential web browser exploitation.
Author: Arnim Rupp (Nextron Systems)
· 2026-06-15 · logsource: category=antivirus · 101a1877-2cf4-474d-abfd-7f6ac4788d1a
Detects a highly relevant Antivirus alert that reports APT malware.
This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-08-31 · logsource: product=windows category=process_creation · 146aace8-9bd6-42ba-be7a-0070d8027b76
Detects potentially suspicious child processes of WinRAR.exe.
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC
· 2021-10-15 (modified 2022-10-05) · logsource: product=linux category=process_creation · 21541900-27a9-4454-9c4c-3f0a4240344a
Rule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell.
SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including
Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
Author: Florian Roth (Nextron Systems), Arnim Rupp
· 2018-09-09 (modified 2026-06-15) · logsource: category=antivirus · 238527ad-3c2c-4e4f-a1f6-92fd63adb864
Detects a highly relevant Antivirus alert that reports an exploitation framework.
This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
Author: Florian Roth
· 2025-01-18 · logsource: product=linux category=process_creation · 297241f3-8108-4b3a-8c15-2dda9f844594
Detects the execution of a shell as sub process of "rsync" without the expected command line flag "-e" being used, which could be an indication of exploitation as described in CVE-2024-12084. This behavior is commonly associated with attempts to execute arbitrary commands or escalate privileges, potentially leading to unauthorized access or further exploitation.
Author: Sittikorn S, frack113
· 2021-07-16 (modified 2023-08-17) · logsource: product=windows category=registry_set · 32b5db62-cb5f-4266-9639-0fa48376ac00
Detects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-06-12 (modified 2024-03-12) · logsource: product=windows category=network_connection · 3c21219b-49b5-4268-bce6-c914ed50f09c
Detects network connections from "dfsvc.exe" used to handled ClickOnce applications to non-local IPs
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-05-20 · logsource: category=webserver · 41956f7c-7a6b-46d6-b6bb-da6eb2e83fbe
Detects potential exploitation of a chained vulnerability attack targeting Ivanti EPMM 12.5.0.0.
CVE-2025-4427 allows unauthenticated access to protected API endpoints via an authentication bypass,
which can then be leveraged to trigger CVE-2025-4428 — a remote code execution vulnerability through
template injection. This sequence enables unauthenticated remote code execution, significantly increasing
the impact of exploitation.
Author: Huntress Labs, Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-10-31 · logsource: product=windows category=process_creation · 43259cc4-1b80-4931-bd98-baea01afc196
Detects the creation of command-line interpreters (cmd.exe, powershell.exe) as child processes of Windows Server Update Services (WSUS) related process wsusservice.exe.
This behavior is a key indicator of exploitation for the critical remote code execution vulnerability such as CVE-2025-59287, where attackers spawn shells to conduct reconnaissance and further post-exploitation activities.
Author: Florian Roth (Nextron Systems), Zach Mathis
· 2020-01-15 (modified 2022-10-22) · logsource: product=windows service=application · 48d91a3a-2363-43ba-a456-ca71ac3da5c2
Detects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited.
MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability.
Unfortunately, that is about the only instance of CVEs being written to this log.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-06-12 (modified 2024-01-31) · logsource: product=windows category=network_connection · 4c5fba4a-9ef6-4f16-823d-606246054741
Detects an initiated network connection over uncommon ports from "dfsvc.exe". A utility used to handled ClickOnce applications.
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-11-25 · logsource: product=windows category=process_creation · 5299fadf-f228-4526-8274-251db1960be9
Detects the execution of `bun_environment.js` via the Bun runtime, a behavior associated with the Shai-Hulud "Second Coming" NPM supply chain attack.
The malware uses a `setup_bun.js` script to install the Bun runtime if not present, and then executes the malicious `bun_environment.js` payload.
Author: Florian Roth (Nextron Systems)
· 2017-11-23 (modified 2021-11-27) · logsource: product=windows category=process_creation · 678eb5f4-8597-4be6-8be7-905e4234b53a
Detects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC
· 2021-10-15 (modified 2022-10-05) · logsource: product=linux category=process_creation · 6eea1bf6-f8d2-488a-a742-e6ef6c1b67db
Rule to detect the use of the SCX RunAsProvider ExecuteScript to execute any UNIX/Linux script using the /bin/sh shell.
Script being executed gets created as a temp file in /tmp folder with a scx* prefix.
Then it is invoked from the following directory /etc/opt/microsoft/scx/conf/tmpdir/.
The file in that directory has the same prefix scx*. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including
Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
Author: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems)
· 2021-11-10 (modified 2025-10-17) · logsource: product=windows category=network_connection · 75e33ce3-ae32-4dcc-9aa8-a2a3029d6f84
Detects an office application (Word, Excel, PowerPoint) that initiate a network connection to a non-private IP addresses.
This rule aims to detect traffic similar to one seen exploited in CVE-2021-42292.
This rule will require an initial baseline and tuning that is specific to your organization.
Author: Florian Roth (Nextron Systems)
· 2018-02-22 (modified 2021-11-27) · logsource: product=windows category=process_creation · 864403a1-36c9-40a2-a982-4c9a45f7d833
Detects Winword starting uncommon sub process FLTLDR.exe as used in exploits for CVE-2017-0261 and CVE-2017-0262
Author: Micah Babinski
· 2025-11-25 · logsource: product=windows category=process_creation · 8e95e73e-ba02-4a87-b4d7-0929b8053038
Detects script interpreters, command-line tools, and similar suspicious child processes of ArcSOC.exe.
ArcSOC.exe is the process name which hosts ArcGIS Server REST services. If an attacker compromises an ArcGIS
Server system and uploads a malicious Server Object Extension (SOE), they can send crafted requests to the corresponding
service endpoint and remotely execute code from the ArcSOC.exe process.
Author: Florian Roth (Nextron Systems)
· 2019-01-16 (modified 2023-02-01) · logsource: product=windows category=process_creation · 8f88e3f6-2a49-48f5-a5c4-2f7eedf78710
Detects a JAVA process running with remote debugging allowing more than just localhost to connect
Author: Arnim Rupp (Nextron Systems)
· 2026-06-15 · logsource: category=antivirus · 97233998-3838-4581-88c6-f1d19d3993fb
Detects a highly relevant Antivirus alert that reports a remote access tool.
This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
Author: Aayush Gupta
· 2025-06-17 · logsource: product=linux category=process_creation · a2d9e2f3-0f43-4c7a-bcd9-9acfc0d723aa
Detects suspicious use of command-line tools such as curl or wget to download remote
content - particularly scripts - into temporary directories (e.g., /dev/shm, /tmp), followed by
immediate execution, indicating potential malicious activity. This pattern is commonly used
by malicious scripts, stagers, or downloaders in fileless or multi-stage Linux attacks.
Author: Max Altgelt (Nextron Systems)
· 2022-04-14 (modified 2024-05-31) · logsource: product=windows category=network_connection · a66bc059-c370-472c-a0d7-f8fd1bf9d583
Detects network connections from the Equation Editor process "eqnedt32.exe".
Author: Nate Guagenti (neu5ron)
· 2021-09-20 (modified 2025-11-03) · logsource: product=zeek service=http · ab6b1a39-a9ee-4ab4-b075-e83acf6e346b
Detects the exploitation of OMIGOD (CVE-2021-38647) which allows remote execute (RCE) commands as root with just a single unauthenticated HTTP request.
Verify, successful, exploitation by viewing the HTTP client (request) body to see what was passed to the server (using PCAP).
Within the client body is where the code execution would occur. Additionally, check the endpoint logs to see if suspicious commands or activity occurred within the timeframe of this HTTP request.
Author: Sittikorn S
· 2021-07-16 (modified 2022-10-09) · logsource: product=windows category=file_event · ad7085ac-92e4-4b76-8ce2-276d2c0e68ef
Detects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
Author: Bhabesh Raj
· 2021-03-03 (modified 2022-10-09) · logsource: product=windows category=file_event · b06335b3-55ac-4b41-937e-16b7f5d57dfd
Detects possible successful exploitation for vulnerability described in CVE-2021-26858 by looking for
creation of non-standard files on disk by Exchange Server’s Unified Messaging service
which could indicate dropping web shells or other malicious content
Author: Florian Roth (Nextron Systems)
· 2017-03-13 (modified 2023-05-18) · logsource: category=proxy · b5de2919-b74a-4805-91a7-5049accbaefe
Detects executable downloads from suspicious remote systems
Author: Swachchhanda Shrawan Poudel
· 2024-05-13 · logsource: product=windows category=process_creation · ca5583e9-8f80-46ac-ab91-7f314d13b984
Detects potentially suspicious child processes of KeyScrambler.exe
Author: Bhabesh Raj
· 2021-03-03 (modified 2023-02-07) · logsource: product=windows category=process_creation · cd479ccc-d8f0-4c66-ba7d-e06286f3f887
Detects possible successful exploitation for vulnerability described in CVE-2021-26857 by looking for | abnormal subprocesses spawning by Exchange Server's Unified Messaging service
Author: Justin C. (@endisphotic), @dreadphones (detection), Thomas Patzke (Sigma rule)
· 2021-07-11 (modified 2024-12-01) · logsource: product=windows category=process_creation · dcdbc940-0bff-46b2-95f3-2d73f848e33b
Detects suspicious print spool service (spoolsv.exe) child processes.
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-10-31 · logsource: product=windows service=application · e5f66e87-7d6b-404f-92fe-7aa67814b5cd
Detects cast exceptions in Windows Server Update Services (WSUS) application logs that highly indicate exploitation attempts of CVE-2025-59287, a deserialization vulnerability in WSUS.
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-11-25 · logsource: product=linux category=process_creation · eb827bbd-670a-4d58-8446-c464d8ac2323
Detects the execution of `bun_environment.js` via the Bun runtime, a behavior associated with the Shai-Hulud "Second Coming" NPM supply chain attack.
The malware uses a `setup_bun.js` script to install the Bun runtime if not present, and then executes the malicious `bun_environment.js` payload.
Author: Nasreddine Bencherchali (Nextron Systems), Andreas Braathen (mnemonic.io)
· 2023-08-30 (modified 2024-01-22) · logsource: product=windows category=process_creation · ec3a3c2f-9bb0-4a9b-8f4b-5ec386544343
Detects exploitation attempt of CVE-2023-38331 (WinRAR before v6.23), where an attacker can leverage WinRAR to execute arbitrary commands and binaries.
Author: Florian Roth (Nextron Systems)
· 2017-09-15 (modified 2021-11-27) · logsource: product=windows category=process_creation · fdd84c68-a1f6-47c9-9477-920584f94905
Detects Winword starting uncommon sub process csc.exe as used in exploits for CVE-2017-8759