Exploitation for Client Execution T1203
Tactic: Execution
Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.
Events covered
15 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Sysmon | Event ID 3 | Network connection |
| Sysmon | Event ID 7 | Image loaded |
| Sysmon | Event ID 11 | FileCreate |
| Sysmon | Event ID 13 | RegistryEvent (Value Set) |
| Sysmon | Event ID 22 | DNSEvent (DNS query) |
| Security-Auditing | Event ID 4663 | An attempt was made to access an object. |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| Security-Auditing | Event ID 5156 | The Windows Filtering Platform has permitted a connection. |
| Defender-DeviceFileEvents | FileCreated | File created |
| Defender-DeviceNetworkEvents | any | Network activity (any) |
| Defender-DeviceProcessEvents | any | Process activity (any) |
| ESF | exec | Process Execution (Notify) |
| Audit-CVE | Event ID 1 | Possible detection of CVE: PossibleDetectionOfCVE. |
| Sysmon-for-Linux | Event ID 1 | Process Create |
Authoring guide
Patterns shared across the 106 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (108 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (972 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (297 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 33 rules
- Antivirus Exploitation Framework Detection
- Audit CVE Event
- CVE-2021-26858 Exchange Exploitation
- CVE-2021-31979 CVE-2021-33771 Exploits
- CVE-2021-31979 CVE-2021-33771 Exploits by Sourgum
- CVE-2023-38331 Exploitation Attempt - Suspicious WinRAR Child Process
- Dfsvc.EXE Initiated Network Connection Over Uncommon Port
- Dfsvc.EXE Network Connection To Non-Local IPs
- Download From Suspicious TLD - Blacklist
- Download From Suspicious TLD - Whitelist
- Droppers Exploiting CVE-2017-11882
- Exploit for CVE-2017-0261
- Exploit for CVE-2017-8759
- Exploitation Activity of CVE-2025-59287 - WSUS Deserialization
- Exploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Process
- Java Running with Remote Debugging
- Network Connection Initiated By Eqnedt32.EXE
- Office Application Initiated Network Connection To Non-Local IP
- OMIGOD HTTP No Authentication RCE - CVE-2021-38647
- OMIGOD SCX RunAsProvider ExecuteScript
- OMIGOD SCX RunAsProvider ExecuteShellCommand
- Potential CVE-2021-26857 Exploitation Attempt
- Potential Exploitation of CVE-2025-4427/4428 Ivanti EPMM Pre-Auth RCE
- Potentially Suspicious Child Process of KeyScrambler.exe
- Potentially Suspicious Child Process Of WinRAR.EXE
- Shai-Hulud Malicious Bun Execution
- Shai-Hulud Malicious Bun Execution - Linux
- Suspicious ArcSOC.exe Child Process
- Suspicious Browser Child Process - MacOS
- Suspicious Download and Execute Pattern via Curl/Wget
- Suspicious HWP Sub Processes
- Suspicious Invocation of Shell via Rsync
- Suspicious Spool Service Child Process
Elastic 29 rules
- Anomalous Windows Process Creation
- Creation of SettingContent-ms Files
- Cupsd or Foomatic-rip Shell Execution
- Execution of File Written or Modified by Microsoft Office
- Exploit - Detected - Elastic Endgame
- Exploit - Prevented - Elastic Endgame
- File Creation by Cups or Foomatic-rip Child
- Network Connection by Cups or Foomatic-rip Child
- Potential CVE-2025-33053 Exploitation
- Potential Foxmail Exploitation
- Potential Git CVE-2025-48384 Exploitation
- Potential JAVA/JNDI Exploitation Attempt
- Potential Notepad Markdown RCE Exploitation
- Potential SAP NetWeaver Exploitation
- Potential SAP NetWeaver WebShell Creation
- Potential Shell via Wildcard Injection Detected
- Printer User (lp) Shell Execution
- Segfault Detected
- Segfault from Sensitive Process Detected
- Suspicious Browser Child Process
- Suspicious Communication App Child Process
- Suspicious Execution from Foomatic-rip or Cupsd Parent
- Suspicious macOS MS Office Child Process
- Suspicious MS Office Child Process
- Suspicious Outlook Child Process
- Suspicious PDF Reader Child Process
- Suspicious Zoom Child Process
- Unusual Executable File Creation by a System Critical Process
- WPS Office Exploitation via DLL Hijack
Splunk 17 rules
- Abuse EQNEDT32.EXE (EDR)
- Abuse EQNEDT32.EXE (Sysmon)
- Abuse EQNEDT32.EXE (Windows Event Log)
- Cisco Secure Firewall - Binary File Type Download
- Cisco Secure Firewall - Blocked Connection
- Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt
- Cisco Secure Firewall - High Priority Intrusion Classification
- Cisco Secure Firewall - Malware File Downloaded
- Cisco Secure Firewall - Possibly Compromised Host
- Cisco Secure Firewall - Repeated Blocked Connections
- Detect Windows DNS SIGRed via Splunk Stream
- Detect Windows DNS SIGRed via Zeek
- Potential Follina_DogWalk Activity - mdst.exe (Sysmon)
- Sunburst Correlation DLL and Network Event
- Suspicious process Spawned by Java (Windows Event Log)
- Windows MSC EvilTwin Directory Path Manipulation
- Windows Remote Image Load
Kusto 24 rules
- AFD WAF - Code Injection
- AFD WAF - Path Traversal Attack
- Antivirus Detected an Infected File
- App Gateway WAF - Scanner Detection
- App Gateway WAF - XSS Detection
- App GW WAF - Code Injection
- App GW WAF - Path Traversal Attack
- Application Gateway WAF - XSS Detection
- BitSight - compromised systems detected
- BitSight - diligence risk category detected
- Detect CVE exploits on network for which a device is vulnerable
- Detect port misuse by anomaly based detection (ASIM Network Session schema)
- Detect port misuse by static threshold (ASIM Network Session schema)
- Detect web requests to potentially harmful files (ASIM Web Session)
- Execution of software vulnerable to webp buffer overflow of CVE-2023-4863
- Front Door Premium WAF - XSS Detection
- GitHub Security Vulnerability in Repository
- Malformed user agent
- New UserAgent observed in last 24 hours
- Office Apps Launching Wscipt
- PE file dropped in Color Profile Folder
- Prestige ransomware IOCs Oct 2022
- Vulnerable Machines related to log4j CVE-2021-44228
- Vulnerable Machines related to OMIGOD CVE-2021-38647