Techniques › T1203 › AN0797
AN0797 Analytic 0797
Windows · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Cause→effect chain: (1) A client app (browser, Office, PDF/Flash/reader) experiences a crash/abnormal exit or loads from an unusual location, then (2) drops or modifies a file in user-writable paths, and/or (3) spawns an unexpected child (e.g., powershell/cmd/mshta/rundll32/wscript/installer), and (4) establishes outbound C2-like connections shortly after. Correlate application logs, file writes, process lineage, and network egress within a short window.</p>
- Detects
- T1203 Exploitation for Client Execution
- Part of
- DET0287 Exploitation for Client Execution – cross-platform behavior chain (browser/Office/3rd-party apps)
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| WinEventLog:Application | EventCode=1000 | DC0038 Application Log Content |
| WinEventLog:Sysmon | EventCode=11 | DC0039 File Creation |
| WinEventLog:Sysmon | EventCode=1 | DC0032 Process Creation |
| WinEventLog:Sysmon | EventCode=3, 22 | DC0082 Network Connection Creation |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
TimeWindow | Correlation window (e.g., 15m) between crash/write/child/network. |
HighRiskChildren | List of child processes that should rarely spawn from Office/browsers (powershell.exe, cmd.exe, wscript.exe, mshta.exe, rundll32.exe, regsvr32.exe, msiexec.exe, curl.exe). |
UserPaths | Writable paths to watch (Downloads, %TEMP%, %APPDATA%, OneDrive, Office startup folders). |
AllowedPlugins | Known add-ins/extensions and updater binaries to reduce noise. |
EgressAllowlist | Known update/CDN domains and proxy egress CIDRs for suppression. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2015-5119 | Adobe Flash Player | Mapped |
| CVE-2018-4939 | Adobe ColdFusion | Mapped |
| CVE-2021-21148 | Google Chromium V8 | Mapped |
| CVE-2021-21166 | Google Chromium | Mapped |
| CVE-2021-21206 | Google Chromium Blink | Mapped |
| CVE-2021-27059 | Microsoft Office | Mapped |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | Mapped |
| CVE-2021-30554 | Google Chromium WebGL | Mapped |
| CVE-2021-37975 | Google Chromium V8 | Mapped |
| CVE-2021-39144 | XStream XStream | Mapped |
| CVE-2022-20701 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Mapped |
| CVE-2022-20703 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Mapped |
| CVE-2022-23748 | Audinate Dante Discovery | Mapped |
| CVE-2022-41128 | Microsoft Windows | Mapped |
| CVE-2022-43769 | Hitachi Vantara Pentaho Business Analytics (BA) Server | Mapped |
| CVE-2023-21608 | Adobe Acrobat and Reader | Mapped |
| CVE-2023-23397 | Microsoft Office | Mapped |
| CVE-2023-26369 | Adobe Acrobat and Reader | Mapped |
| CVE-2023-34048 | VMware vCenter Server | Mapped |
| CVE-2023-36844 | Juniper Junos OS | Mapped |
| CVE-2023-47565 | QNAP VioStor NVR | Mapped |
| CVE-2023-49897 | FXC AE1021, AE1021PE | Mapped |
| CVE-2024-11120 | GeoVision Multiple Devices | Mapped |
| CVE-2024-26169 | Microsoft Windows | Mapped |
| CVE-2024-45195 | Apache OFBiz | Mapped |
| CVE-2024-5274 | Google Chromium V8 | Mapped |
| CVE-2025-24016 | Wazuh Wazuh Server | Mapped |
| CVE-2025-24993 | Microsoft Windows | Mapped |
| CVE-2025-27038 | Qualcomm Multiple Chipsets | Mapped |
| CVE-2025-2783 | Google Chromium Mojo | Mapped |
| CVE-2025-30397 | Microsoft Windows | Mapped |
| CVE-2025-30406 | Gladinet CentreStack | Mapped |
| CVE-2025-31200 | Apple Multiple Products | Stale |
| CVE-2025-31201 | Apple Multiple Products | Stale |
| CVE-2025-3248 | Langflow Langflow | Mapped |
| CVE-2025-3935 | ConnectWise ScreenConnect | Mapped |
| CVE-2025-42999 | SAP NetWeaver | Mapped |
| CVE-2025-43200 | Apple Multiple Products | Mapped |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) | Mapped |
| CVE-2025-5419 | Google Chromium V8 | Mapped |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway | Mapped |
| CVE-2025-6554 | Google Chromium V8 | Mapped |
| CVE-2025-6558 | Google Chromium | Mapped |