Coverage › CVE-2015-3043
CVE-2015-3043 Mapped Sigma
Adobe Flash Player Memory Corruption Vulnerability
- Vendor / product
- Adobe — Flash Player
- Description (CISA)
- A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.
- Added to KEV
- 2022-03-03
- Due date
- 2022-03-24
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Known ransomware use
- Unknown
- CWE
- CWE-787
- CISA notes
- https://nvd.nist.gov/vuln/detail/CVE-2015-3043
- Elsewhere
- cve.org · NVD · CISA KEV · JSON
ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28
3 mapping objects across 3 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such.
| Technique | Mapping type | CTID comment | Status in v19.2 |
|---|---|---|---|
| T1189 Drive-by Compromise | exploitation technique | This vulnerability is exploited by a maliciously-crafted .swf file which can be run on a user system via drive-by compromise. ref 1 |
live |
| T1204.002 Malicious File | exploitation technique | This vulnerability is exploited by a maliciously-crafted .swf file which can be run on a user system. ref 1 |
live |
| T1499.004 Application or System Exploitation | primary impact | This vulnerability is exploited by a maliciously-crafted .swf file which can be run on a user system. ref 1 |
live |
Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources
T1189 Drive-by Compromise exploitation technique
- DET0176 Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189)
AN0498 WindowsCorrelated evidence of anomalous browser/network behavior (suspicious external resource fetches and script injection patterns) followed by atypical child processes, ephemeral execution contexts, memory modification or process injection, and unexpected file drops. Defender sees network requests to previously unseen/suspicious domains or resources + browser process spawning unusual children or loading unsigned modules + file writes or registry changes shortly after those requests.WinEventLog:Application
Browser or plugin/application logs showing script errors, plugin enumerations, or unusual extension load events→ DC0038 Application Log Contentetw:Microsoft-Windows-Kernel-ProcessMemory Modification / Unmapped module load or suspicious RWX allocations in the process space of a browser process→ DC0020 Process ModificationNSM:Flowhttp.request: HTTP requests and responses for specific script resources, unexpected content-types (application/octet-stream for script URLs), suspicious referrers, or obfuscated javascript resources→ DC0085 Network Traffic ContentTunable:TimeWindowKnownGoodDomainsListPayloadEntropyThresholdUserContextAN0499 LinuxCorrelated evidence of browser or webview fetches to uncommon domains or mutated JS resources (proxy/NGFW logs + Zeek/HTTP logs) followed by unexpected interpreters or script engines executing (python, ruby, sh) spawned from browser processes or user sessions, rapid on-disk staging in /tmp, and outbound connections that deviate from baseline. Defender sees: uncommon resource fetch → short-lived child process executions from user browser context → file writes in temp directories → anomalous outbound C2-like connections.auditd:SYSCALLexecve: execve calls where a browser/webview process is parent and child is interpreter (python, sh, ruby) or downloader (curl, wget)→ DC0032 Process Creationlinux:syslogApplication or browser logs (webview errors, plugin enumerations) indicating suspicious script evaluation or plugin loads→ DC0038 Application Log ContentNSM:Flowhttp::response: HTTP responses with suspicious content-type for scripts, long obfuscated javascript bodies, or redirects to exploit kit domains→ DC0085 Network Traffic Contentlinux:SysmonNew files in /tmp, /var/tmp, $HOME/.cache, executed within TimeWindow after browser HTTP fetch→ DC0039 File CreationNSM:ConnectionsOutbound connections from newly spawned child processes or from the browser to uncommon endpoints or on anomalous ports→ DC0082 Network Connection CreationTunable:TempPathPatternsUserShellWhitelistDomainRarityThresholdAN0500 macOSCorrelated evidence where Safari/Chrome/WebKit-based processes issue network requests for uncommon or obfuscated JS resources followed by spawning of script interpreters, launchd or ad-hoc binaries, unusual child processes, or dynamic library loads into browser processes. Defender sees: proxy/HTTP logs with suspicious resource content + unifiedlogs/ASL showing browser/plugin crashes or extension loads + process events indicating child process creation and file writes to /var/folders or /tmp shortly after the fetch.macos:unifiedlogLogs from unifiedlogging that show browser crashes, plugin enumerations, extension installs or errors around the same time as suspicious network fetches→ DC0038 Application Log Contentmacos:unifiedlogprocess_create: Process creation where parent is Safari/Google Chrome and child is script interpreter or signed-but-unusual helper binary→ DC0032 Process Creationmacos:unifiedlogNew files written to /var/folders, /tmp, ~/Library/Caches, or ~/Downloads by browser context or its children→ DC0039 File CreationNSM:FlowHTTP/HTTPS requests for script resources flagged by content inspection (excessive obfuscation, eval usage, unusual redirects)→ DC0085 Network Traffic Contentmacos:unifiedlogAnomalous dyld dynamic library loads or RWX memory mappings in browser process→ DC0020 Process ModificationTunable:SleepyUserThresholdExtensionInstallPolicyAN0501 Identity ProviderPost-compromise identity & session anomalies that follow a drive-by compromise: token reuse from new/unfamiliar IPs, anomalous sign-in patterns for previously inactive users, unexpected consent/grant events, or provisioning changes. Defender sees an endpoint/browser compromise (network + endpoint signals) followed by unusual IdP events: new refresh token issuance, consent/consent-grant events, odd MFA bypass patterns, or unusual OAuth client registrations.azure:signinlogsSignIn: Sign-ins flagged as atypical (new geographic region, unfamiliar device id) shortly after correlated endpoint/browser compromise times→ DC0002 User Account Authenticationm365:unifiedApplication Consent grants, new OAuth client registrations, or unusual admin-level activities executed by a user account shortly after suspected drive-by compromise→ DC0038 Application Log Contentsaas:authRefresh token issuance or refresh token usage from new IPs or user agents→ DC0013 User Account MetadataAWS:CloudTrailConsoleLogin: If IdP backed by cloud provider, Console login from new IP/agent after correlated endpoint compromise→ DC0067 Logon Session CreationTunable:IdpAlertWindowHighRiskCountryListDeviceTrustLevel
Sigma rules tagged attack.t1189 (3)
Author: Sohan G (D4rkCiph3r)
· 2023-04-05 · logsource: product=macos category=process_creation · 0250638a-2b28-4541-86fc-ea4c558fa0c6
Detects suspicious child processes spawned from browsers. This could be a result of a potential web browser exploitation.
Author: Florian Roth (Nextron Systems)
· 2017-10-25 (modified 2022-08-08) · logsource: category=proxy · 4922a5dd-6743-4fc2-8e81-144374280997
Detects a flashplayer update from an unofficial location
Author: Saw Win Naung, Nasreddine Bencherchali
· 2021-08-15 (modified 2022-06-14) · logsource: category=webserver · 65354b83-a2ea-4ea6-8414-3ab38be0d409
Detects XSS attempts injected via GET requests in access logs
T1204.002 Malicious File exploitation technique
- DET0294 User Execution – Malicious File via download/open → spawn chain (T1204.002)
AN0819 WindowsUser opens a file delivered by email, web, chat, or share. The handler application (Word/PDF reader/archiver) creates a file in user-controlled paths (Downloads, Temp, Desktop) and then spawns a new or unusual child process (e.g., powershell.exe, wscript.exe, cmd.exe, regsvr32.exe, rundll32.exe, msiexec.exe). Optional precursors include FileStreamCreated (URL/UNC) and Office → system32 batch writes.Tunable:
TimeWindowSuspiciousExtensionsUserPathsParentAppsSignerAllowListAN0820 macOSUser opens a downloaded document/installer leading to EndpointSecurity file create in ~/Downloads or ~/Library paths then an exec of a suspicious utility (osascript, bash/zsh, curl, chmod, open with -a Terminal). Correlates File Creation with subsequent process exec and, optionally, quarantine/LSQuarantine events.macos:unifiedlogprocess_exec: image in {/bin/bash,/bin/zsh,/usr/bin/osascript,/usr/bin/python*,/usr/bin/curl,/usr/bin/ssh,/usr/bin/open} AND parent in {Preview, TextEdit, Microsoft Word, Microsoft Excel, AdobeReader, Archive Utility, Finder}→ DC0032 Process Creationmacos:endpointsecurityES_EVENT_TYPE_NOTIFY_CREATE: path under /Users/*/(Downloads|Desktop|Library/*/Containers|Library/Group Containers) AND extension in SuspiciousExtensions→ DC0039 File CreationTunable:TimeWindowQuarantineRequiredParentAppsAN0821 LinuxUser or desktop application writes a new file to ~/Downloads, /tmp, or mounted removable media followed by execve of a risky interpreter/loader (bash, sh, python, perl, php, node, curl|wget piping to sh, ld.so, rdesktop, xdg-open - with unusual args). Uses auditd PATH+SYSCALL (open/creat/write/rename) with execve event linking.auditd:SYSCALLopen/create/rename: name in (/home/*/Downloads/*|/tmp/*|/run/user/*|/media/*) AND ext in SuspiciousExtensions→ DC0039 File Creationauditd:SYSCALLexecve: exe in {/bin/bash,/bin/sh,/usr/bin/python*,/usr/bin/perl,/usr/bin/php,/usr/bin/node,/usr/bin/curl,/usr/bin/wget,/usr/bin/xdg-open,/usr/bin/ssh,/usr/bin/rundll32 (wine)} AND ppid process is a document viewer/browser→ DC0032 Process CreationTunable:TimeWindowDesktopParentMap
Sigma rules tagged attack.t1204.002 (39)
Author: Florian Roth (Nextron Systems)
· 2017-11-07 (modified 2023-05-18) · logsource: category=proxy · 00d0b5ab-1f55-4120-8e83-487c0a7baf19
Detects download of certain file types from hosts in suspicious TLDs
Author: Joseph Kamau
· 2024-05-27 (modified 2025-10-07) · logsource: product=windows category=process_creation · 1193d960-2369-499f-a158-7b50a31df682
Detects when a browser process or browser tab is launched from an application that handles document files such as Adobe, Microsoft Office, etc. And connects to a web application over http(s), this could indicate a possible phishing attempt.
Author: Steffen Rogge (dr0pd34d)
· 2024-07-10 · logsource: product=windows category=image_load · 1337afba-d17d-4d23-bd55-29b927603b30
Detects Microsoft Word loading an Add-In (.wll) file which can be used by threat actors for initial access or persistence.
Author: Michael Haag, Florian Roth (Nextron Systems), Markus Neis, Elastic, FPT.EagleEye Team
· 2022-02-28 (modified 2023-02-04) · logsource: product=windows category=process_creation · 208748f7-881d-47ac-a29c-07ea84bf691d
Detects a suspicious process spawning from an Outlook process.
Author: Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems)
· 2022-08-10 (modified 2025-10-12) · logsource: product=windows category=file_event · 28208707-fe31-437f-9a7f-4b1108b94d2e
Detects the creation of potentially malicious script and executable files in Windows startup folders, which is a common persistence technique used by threat actors.
These files (.ps1, .vbs, .js, .bat, etc.) are automatically executed when a user logs in, making the Startup folder an attractive target for attackers.
This technique is frequently observed in malvertising campaigns and malware distribution where attackers attempt to maintain long-term access to compromised systems.
Author: Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-11-03 · logsource: product=windows service=appxdeployment-server · 289dfa9e-e378-4a56-a9d4-7ed5ee218029
Detects successful MSIX/AppX package installations on Windows systems by monitoring EventID 854 in the Microsoft-Windows-AppXDeployment-Server/Operational log.
While most installations are legitimate, this can help identify unauthorized or suspicious package installations.
It is crucial to monitor such events as threat actors may exploit MSIX/AppX packages to deliver and execute malicious payloads.
Author: Florian Roth (Nextron Systems)
· 2020-05-08 (modified 2023-02-13) · logsource: product=windows category=process_creation · 29fd07fc-9cfd-4331-b7fd-cc18dfa21052
Detects specific process characteristics of Maze ransomware word document droppers
Author: Leonardo Gasparini
· 2026-05-12 · logsource: product=linux category=process_creation · 3c6f5e4a-8d0b-6abc-d9e2-4f7a6b8c9d0e
Detects process execution indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai and uipath reported on early May 2026.
The preinstall hook runs setup.mjs, which downloads a platform-specific Bun runtime.
Author: Pushkarev Dmitry
· 2020-06-28 (modified 2025-12-03) · logsource: product=windows service=applocker · 401e5d00-b944-11ea-8f9a-00163ecd60ae
Detects when AppLocker prevents the execution of an Application, DLL, Script, MSI, or Packaged-App from running.
Author: Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io
· 2018-04-06 (modified 2023-04-24) · logsource: product=windows category=process_creation · 438025f9-5856-4663-83f7-52f878a70a50
Detects a suspicious process spawning from one of the Microsoft Office suite products (Word, Excel, PowerPoint, Publisher, Visio, etc.)
Author: Florian Roth (Nextron Systems)
· 2017-10-25 (modified 2022-08-08) · logsource: category=proxy · 4922a5dd-6743-4fc2-8e81-144374280997
Detects a flashplayer update from an unofficial location
Author: heyyanu
· 2026-03-26 · logsource: product=windows service=applocker · 557e3bd3-7f21-495d-8d50-7c8bdfb8041c
Detects when AppLocker "Audit only" enforcement mode reports that an Application, DLL, Script, MSI, or Packaged-App would have been blocked if AppLocker "Enforce rules" enforcement mode was enabled.
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)
· 2020-05-02 (modified 2023-08-17) · logsource: product=windows category=registry_set · 60936b49-fca0-4f32-993d-7415edcf9a5d
A General detection for a new application in AppCompat. This indicates an application executing for the first time on an endpoint.
Author: Florian Roth (Nextron Systems)
· 2017-11-23 (modified 2021-11-27) · logsource: product=windows category=process_creation · 678eb5f4-8597-4be6-8be7-905e4234b53a
Detects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe
Author: Sohan G (D4rkCiph3r)
· 2023-01-31 (modified 2023-02-04) · logsource: product=macos category=process_creation · 69483748-1525-4a6c-95ca-90dc8d431b68
Detects suspicious child processes spawning from microsoft office suite applications such as word or excel. This could indicates malicious macro execution
All 39 rules on the technique page →
T1499.004 Application or System Exploitation primary impact
- DET0304 Detection Strategy for Endpoint DoS via Application or System Exploitation
AN0850 WindowsExploitation of system or application vulnerability (e.g., CVE-based exploit) followed by service crash, restart, or repeated failure within a short time frame, impacting application/system availability.Tunable:
TimeWindowTargetApplicationAN0851 LinuxUser or remote input triggers application crash or segmentation fault (e.g., SIGSEGV) with service recovery attempts, observed via audit logs and systemd journaling.auditd:SYSCALLProcess segfault or abnormal termination after invoking vulnerable syscall sequence→ DC0033 Process Terminationjournald:ApplicationSegfault or crash log entry associated with specific application binary→ DC0038 Application Log ContentNSM:FlowUnusual request pattern leading up to service crash (e.g., malformed or oversized payload)→ DC0085 Network Traffic ContentTunable:CrashPatternExploitSourceIPAN0852 macOSApplication crash or repeated restart cycle triggered by malformed input or exploit file, observed via unified logs and process crash monitoring.macos:unifiedlogCrash log entries for a process receiving malformed input or known exploit patterns→ DC0038 Application Log Contentmacos:unifiedlogUnusual child process tree indicating attempted recovery after crash→ DC0032 Process CreationTunable:CrashSignatureInputVectorAN0853 IaaSCloud workload exploitation leads to repeated container, service, or VM termination/restart, typically associated with CVE-based crash triggers or fuzzed payloads.AWS:CloudWatchRepeated crash pattern within container or instance logs→ DC0038 Application Log ContentAWS:VPCFlowLogsLarge volume of malformed or synthetic payloads to application endpoints prior to failure→ DC0085 Network Traffic ContentTunable:CrashThresholdServiceID
Sigma rules tagged attack.t1499.004 (3)
Author: Florian Roth (Nextron Systems)
· 2017-02-28 (modified 2021-11-27) · logsource: service=apache · 1da8ce0b-855d-4004-8860-7d64d42063b1
Detects a segmentation fault error message caused by a crashing apache worker process
Author: Florian Roth (Nextron Systems), Zach Mathis
· 2020-01-15 (modified 2022-10-22) · logsource: product=windows service=application · 48d91a3a-2363-43ba-a456-ca71ac3da5c2
Detects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited.
MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability.
Unfortunately, that is about the only instance of CVEs being written to this log.
Author: Florian Roth (Nextron Systems)
· 2021-05-31 (modified 2023-05-08) · logsource: service=nginx · 59ec40bb-322e-40ab-808d-84fa690d7e56
Detects a core dump of a crashing Nginx worker process, which could be a signal of a serious problem or exploitation attempts.