kevmap

Techniques › T1203

T1203 Exploitation for Client Execution

execution — Linux, macOS, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
3
analytics
35
Sigma rules tagged attack.t1203
43
KEV CVEs mapped here
<p>Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.</p><p>Several types exist:</p><p>### Browser-based Exploitation</p><p>Web browsers are a common target through Drive-by Compromise and Spearphishing Link. Endpoint systems may be compromised through normal web browsing or from certain users being targeted by links in spearphishing emails to adversary controlled sites used to exploit the web browser. These often do not require an action by the user for the exploit to be executed.</p><p>### Office Applications</p><p>Common office and productivity applications such as Microsoft Office are also targeted through Phishing. Malicious files will be transmitted directly as attachments or through links to download them. These require the user to open the document or file for the exploit to run.</p><p>### Common Third-party Applications</p><p>Other applications that are commonly seen or are part of the software deployed in a target network may also be used for exploitation. Applications such as Adobe Reader and Flash, which are common in enterprise environments, have been routinely targeted by adversaries attempting to gain access to systems. Depending on the software and nature of the vulnerability, some may be exploited in the browser or require the user to open a file. For instance, some Flash exploits have been delivered as objects within Microsoft Office documents.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2025-6558Google Chromium exploitation technique Mapped2025-07-22
CVE-2025-6554Google Chromium V8 exploitation technique Mapped2025-07-02
CVE-2025-6543Citrix NetScaler ADC and Gateway exploitation technique Mapped2025-06-30
CVE-2025-43200Apple Multiple Products exploitation technique Mapped2025-06-16
CVE-2025-24016Wazuh Wazuh Server secondary impact Mapped2025-06-10
CVE-2025-5419Google Chromium V8 exploitation technique Mapped2025-06-05
CVE-2025-27038Qualcomm Multiple Chipsets exploitation technique Mapped2025-06-03
CVE-2025-3935ConnectWise ScreenConnect exploitation technique Mapped2025-06-02
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) exploitation technique Mapped2025-05-19
CVE-2025-42999SAP NetWeaver exploitation technique Mapped2025-05-15
CVE-2025-30397Microsoft Windows exploitation technique Mapped2025-05-13
CVE-2024-11120GeoVision Multiple Devices exploitation technique Mapped2025-05-07
CVE-2025-3248Langflow Langflow exploitation technique Mapped2025-05-05
CVE-2025-31201Apple Multiple Products exploitation technique Stale2025-04-17
CVE-2025-31200Apple Multiple Products exploitation technique Stale2025-04-17
CVE-2025-30406Gladinet CentreStack exploitation technique Mapped2025-04-08
CVE-2025-2783Google Chromium Mojo exploitation technique Mapped2025-03-27
CVE-2025-24993Microsoft Windows exploitation technique Mapped2025-03-11
CVE-2022-43769Hitachi Vantara Pentaho Business Analytics (BA) Server exploitation technique Mapped2025-03-03
CVE-2022-23748Audinate Dante Discovery exploitation technique Mapped2025-02-06
CVE-2024-45195Apache OFBiz exploitation technique Mapped2025-02-04
CVE-2024-26169Microsoft Windows exploitation technique Mapped2024-06-13
CVE-2024-5274Google Chromium V8 primary impact Mapped2024-05-28
CVE-2023-34048VMware vCenter Server primary impact Mapped2024-01-22
CVE-2023-49897FXC AE1021, AE1021PE exploitation technique Mapped2023-12-21
CVE-2023-47565QNAP VioStor NVR exploitation technique Mapped2023-12-21
CVE-2023-36844Juniper Junos OS exploitation technique Mapped2023-11-13
CVE-2023-21608Adobe Acrobat and Reader primary impact Mapped2023-10-10
CVE-2023-26369Adobe Acrobat and Reader primary impact Mapped2023-09-14
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU) exploitation technique Mapped2023-07-07
CVE-2023-23397Microsoft Office exploitation technique Mapped2023-03-14
CVE-2021-39144XStream XStream primary impact Mapped2023-03-10
CVE-2022-41128Microsoft Windows primary impact Mapped2022-11-08
CVE-2022-20703Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers exploitation technique Mapped2022-03-03
CVE-2022-20701Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers primary impact Mapped2022-03-03
CVE-2015-5119Adobe Flash Player exploitation technique Mapped2022-03-03
CVE-2018-4939Adobe ColdFusion exploitation technique Mapped2021-11-03
CVE-2021-21166Google Chromium primary impact Mapped2021-11-03
CVE-2021-21148Google Chromium V8 primary impact Mapped2021-11-03
CVE-2021-37975Google Chromium V8 primary impact Mapped2021-11-03
CVE-2021-30554Google Chromium WebGL exploitation technique Mapped2021-11-03
CVE-2021-21206Google Chromium Blink exploitation technique Mapped2021-11-03
CVE-2021-27059Microsoft Office exploitation technique Mapped2021-11-03

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1203

Author: Florian Roth (Nextron Systems) · 2017-11-07 (modified 2023-05-18) · logsource: category=proxy · 00d0b5ab-1f55-4120-8e83-487c0a7baf19
Detects download of certain file types from hosts in suspicious TLDs
Author: Florian Roth (Nextron Systems) · 2019-10-24 (modified 2021-11-27) · logsource: product=windows category=process_creation · 023394c4-29d5-46ab-92b8-6a534c6f447b
Detects suspicious Hangul Word Processor (Hanword) sub processes that could indicate an exploitation
Author: Sohan G (D4rkCiph3r) · 2023-04-05 · logsource: product=macos category=process_creation · 0250638a-2b28-4541-86fc-ea4c558fa0c6
Detects suspicious child processes spawned from browsers. This could be a result of a potential web browser exploitation.
Techniques: T1189T1203T1059
Author: Arnim Rupp (Nextron Systems) · 2026-06-15 · logsource: category=antivirus · 101a1877-2cf4-474d-abfd-7f6ac4788d1a
Detects a highly relevant Antivirus alert that reports APT malware. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
Techniques: T1203T1219.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-08-31 · logsource: product=windows category=process_creation · 146aace8-9bd6-42ba-be7a-0070d8027b76
Detects potentially suspicious child processes of WinRAR.exe.
Techniques: T1203
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC · 2021-10-15 (modified 2022-10-05) · logsource: product=linux category=process_creation · 21541900-27a9-4454-9c4c-3f0a4240344a
Rule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
Techniques: T1068T1190T1203
Author: Florian Roth (Nextron Systems), Arnim Rupp · 2018-09-09 (modified 2026-06-15) · logsource: category=antivirus · 238527ad-3c2c-4e4f-a1f6-92fd63adb864
Detects a highly relevant Antivirus alert that reports an exploitation framework. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
Techniques: T1203T1219.002
Author: Florian Roth · 2025-01-18 · logsource: product=linux category=process_creation · 297241f3-8108-4b3a-8c15-2dda9f844594
Detects the execution of a shell as sub process of "rsync" without the expected command line flag "-e" being used, which could be an indication of exploitation as described in CVE-2024-12084. This behavior is commonly associated with attempts to execute arbitrary commands or escalate privileges, potentially leading to unauthorized access or further exploitation.
Techniques: T1059T1203
Author: Sittikorn S, frack113 · 2021-07-16 (modified 2023-08-17) · logsource: product=windows category=registry_set · 32b5db62-cb5f-4266-9639-0fa48376ac00
Detects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
Techniques: T1566T1203
CVE tags: CVE-2021-33771CVE-2021-31979
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-06-12 (modified 2024-03-12) · logsource: product=windows category=network_connection · 3c21219b-49b5-4268-bce6-c914ed50f09c
Detects network connections from "dfsvc.exe" used to handled ClickOnce applications to non-local IPs
Techniques: T1203
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-05-20 · logsource: category=webserver · 41956f7c-7a6b-46d6-b6bb-da6eb2e83fbe
Detects potential exploitation of a chained vulnerability attack targeting Ivanti EPMM 12.5.0.0. CVE-2025-4427 allows unauthenticated access to protected API endpoints via an authentication bypass, which can then be leveraged to trigger CVE-2025-4428 — a remote code execution vulnerability through template injection. This sequence enables unauthenticated remote code execution, significantly increasing the impact of exploitation.
Techniques: T1190T1203
CVE tags: CVE-2025-4427CVE-2025-4428
Author: Huntress Labs, Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-10-31 · logsource: product=windows category=process_creation · 43259cc4-1b80-4931-bd98-baea01afc196
Detects the creation of command-line interpreters (cmd.exe, powershell.exe) as child processes of Windows Server Update Services (WSUS) related process wsusservice.exe. This behavior is a key indicator of exploitation for the critical remote code execution vulnerability such as CVE-2025-59287, where attackers spawn shells to conduct reconnaissance and further post-exploitation activities.
Techniques: T1190T1203
CVE tags: CVE-2025-59287
Audit CVE Event criticaltest
Author: Florian Roth (Nextron Systems), Zach Mathis · 2020-01-15 (modified 2022-10-22) · logsource: product=windows service=application · 48d91a3a-2363-43ba-a456-ca71ac3da5c2
Detects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited. MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability. Unfortunately, that is about the only instance of CVEs being written to this log.
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-06-12 (modified 2024-01-31) · logsource: product=windows category=network_connection · 4c5fba4a-9ef6-4f16-823d-606246054741
Detects an initiated network connection over uncommon ports from "dfsvc.exe". A utility used to handled ClickOnce applications.
Techniques: T1203
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-11-25 · logsource: product=windows category=process_creation · 5299fadf-f228-4526-8274-251db1960be9
Detects the execution of `bun_environment.js` via the Bun runtime, a behavior associated with the Shai-Hulud "Second Coming" NPM supply chain attack. The malware uses a `setup_bun.js` script to install the Bun runtime if not present, and then executes the malicious `bun_environment.js` payload.
Techniques: T1195.002T1203
Author: Florian Roth (Nextron Systems) · 2017-11-23 (modified 2021-11-27) · logsource: product=windows category=process_creation · 678eb5f4-8597-4be6-8be7-905e4234b53a
Detects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe
CVE tags: CVE-2017-11882
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC · 2021-10-15 (modified 2022-10-05) · logsource: product=linux category=process_creation · 6eea1bf6-f8d2-488a-a742-e6ef6c1b67db
Rule to detect the use of the SCX RunAsProvider ExecuteScript to execute any UNIX/Linux script using the /bin/sh shell. Script being executed gets created as a temp file in /tmp folder with a scx* prefix. Then it is invoked from the following directory /etc/opt/microsoft/scx/conf/tmpdir/. The file in that directory has the same prefix scx*. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
Techniques: T1068T1190T1203
Author: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems) · 2021-11-10 (modified 2025-10-17) · logsource: product=windows category=network_connection · 75e33ce3-ae32-4dcc-9aa8-a2a3029d6f84
Detects an office application (Word, Excel, PowerPoint) that initiate a network connection to a non-private IP addresses. This rule aims to detect traffic similar to one seen exploited in CVE-2021-42292. This rule will require an initial baseline and tuning that is specific to your organization.
Techniques: T1203
Author: Florian Roth (Nextron Systems) · 2018-02-22 (modified 2021-11-27) · logsource: product=windows category=process_creation · 864403a1-36c9-40a2-a982-4c9a45f7d833
Detects Winword starting uncommon sub process FLTLDR.exe as used in exploits for CVE-2017-0261 and CVE-2017-0262
CVE tags: CVE-2017-0261
Author: Micah Babinski · 2025-11-25 · logsource: product=windows category=process_creation · 8e95e73e-ba02-4a87-b4d7-0929b8053038
Detects script interpreters, command-line tools, and similar suspicious child processes of ArcSOC.exe. ArcSOC.exe is the process name which hosts ArcGIS Server REST services. If an attacker compromises an ArcGIS Server system and uploads a malicious Server Object Extension (SOE), they can send crafted requests to the corresponding service endpoint and remotely execute code from the ArcSOC.exe process.
Techniques: T1059T1203
Author: Florian Roth (Nextron Systems) · 2019-01-16 (modified 2023-02-01) · logsource: product=windows category=process_creation · 8f88e3f6-2a49-48f5-a5c4-2f7eedf78710
Detects a JAVA process running with remote debugging allowing more than just localhost to connect
Techniques: T1203
Author: Arnim Rupp (Nextron Systems) · 2026-06-15 · logsource: category=antivirus · 97233998-3838-4581-88c6-f1d19d3993fb
Detects a highly relevant Antivirus alert that reports a remote access tool. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
Techniques: T1203T1219.002
Author: Aayush Gupta · 2025-06-17 · logsource: product=linux category=process_creation · a2d9e2f3-0f43-4c7a-bcd9-9acfc0d723aa
Detects suspicious use of command-line tools such as curl or wget to download remote content - particularly scripts - into temporary directories (e.g., /dev/shm, /tmp), followed by immediate execution, indicating potential malicious activity. This pattern is commonly used by malicious scripts, stagers, or downloaders in fileless or multi-stage Linux attacks.
Techniques: T1059.004T1203
Author: Max Altgelt (Nextron Systems) · 2022-04-14 (modified 2024-05-31) · logsource: product=windows category=network_connection · a66bc059-c370-472c-a0d7-f8fd1bf9d583
Detects network connections from the Equation Editor process "eqnedt32.exe".
Techniques: T1203
Author: Nate Guagenti (neu5ron) · 2021-09-20 (modified 2025-11-03) · logsource: product=zeek service=http · ab6b1a39-a9ee-4ab4-b075-e83acf6e346b
Detects the exploitation of OMIGOD (CVE-2021-38647) which allows remote execute (RCE) commands as root with just a single unauthenticated HTTP request. Verify, successful, exploitation by viewing the HTTP client (request) body to see what was passed to the server (using PCAP). Within the client body is where the code execution would occur. Additionally, check the endpoint logs to see if suspicious commands or activity occurred within the timeframe of this HTTP request.
CVE tags: CVE-2021-38647
Author: Sittikorn S · 2021-07-16 (modified 2022-10-09) · logsource: product=windows category=file_event · ad7085ac-92e4-4b76-8ce2-276d2c0e68ef
Detects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
Techniques: T1566T1203
CVE tags: CVE-2021-33771CVE-2021-31979
Author: Bhabesh Raj · 2021-03-03 (modified 2022-10-09) · logsource: product=windows category=file_event · b06335b3-55ac-4b41-937e-16b7f5d57dfd
Detects possible successful exploitation for vulnerability described in CVE-2021-26858 by looking for creation of non-standard files on disk by Exchange Server’s Unified Messaging service which could indicate dropping web shells or other malicious content
Techniques: T1203
CVE tags: CVE-2021-26858
Author: Florian Roth (Nextron Systems) · 2017-03-13 (modified 2023-05-18) · logsource: category=proxy · b5de2919-b74a-4805-91a7-5049accbaefe
Detects executable downloads from suspicious remote systems
Author: Swachchhanda Shrawan Poudel · 2024-05-13 · logsource: product=windows category=process_creation · ca5583e9-8f80-46ac-ab91-7f314d13b984
Detects potentially suspicious child processes of KeyScrambler.exe
Techniques: T1203T1574.001
Author: Bhabesh Raj · 2021-03-03 (modified 2023-02-07) · logsource: product=windows category=process_creation · cd479ccc-d8f0-4c66-ba7d-e06286f3f887
Detects possible successful exploitation for vulnerability described in CVE-2021-26857 by looking for | abnormal subprocesses spawning by Exchange Server's Unified Messaging service
Techniques: T1203
CVE tags: CVE-2021-26857
Author: Justin C. (@endisphotic), @dreadphones (detection), Thomas Patzke (Sigma rule) · 2021-07-11 (modified 2024-12-01) · logsource: product=windows category=process_creation · dcdbc940-0bff-46b2-95f3-2d73f848e33b
Detects suspicious print spool service (spoolsv.exe) child processes.
Techniques: T1203T1068
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-10-31 · logsource: product=windows service=application · e5f66e87-7d6b-404f-92fe-7aa67814b5cd
Detects cast exceptions in Windows Server Update Services (WSUS) application logs that highly indicate exploitation attempts of CVE-2025-59287, a deserialization vulnerability in WSUS.
Techniques: T1190T1203
CVE tags: CVE-2025-59287
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-11-25 · logsource: product=linux category=process_creation · eb827bbd-670a-4d58-8446-c464d8ac2323
Detects the execution of `bun_environment.js` via the Bun runtime, a behavior associated with the Shai-Hulud "Second Coming" NPM supply chain attack. The malware uses a `setup_bun.js` script to install the Bun runtime if not present, and then executes the malicious `bun_environment.js` payload.
Techniques: T1195.002T1203
Author: Nasreddine Bencherchali (Nextron Systems), Andreas Braathen (mnemonic.io) · 2023-08-30 (modified 2024-01-22) · logsource: product=windows category=process_creation · ec3a3c2f-9bb0-4a9b-8f4b-5ec386544343
Detects exploitation attempt of CVE-2023-38331 (WinRAR before v6.23), where an attacker can leverage WinRAR to execute arbitrary commands and binaries.
Techniques: T1203
CVE tags: CVE-2023-38331
Author: Florian Roth (Nextron Systems) · 2017-09-15 (modified 2021-11-27) · logsource: product=windows category=process_creation · fdd84c68-a1f6-47c9-9477-920584f94905
Detects Winword starting uncommon sub process csc.exe as used in exploits for CVE-2017-8759
CVE tags: CVE-2017-8759