Exploitation for Client Execution T1203

Tactic: Execution

Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.

Events covered

29 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 7Image loaded
SysmonEvent ID 11FileCreate
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 22DNSEvent (DNS query)
SysmonEvent ID 23FileDelete (File Delete archived)
SysmonEvent ID 26FileDeleteDetected (File Delete logged)
Security-AuditingEvent ID 4663An attempt was made to access an object.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 5152The Windows Filtering Platform blocked a packet.
Security-AuditingEvent ID 5154The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.
Security-AuditingEvent ID 5155The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.
Security-AuditingEvent ID 5156The Windows Filtering Platform has permitted a connection.
Security-AuditingEvent ID 5157The Windows Filtering Platform has blocked a connection.
Security-AuditingEvent ID 5158The Windows Filtering Platform has permitted a bind to a local port.
Security-AuditingEvent ID 5159The Windows Filtering Platform has blocked a bind to a local port.
Defender-DeviceEventsanyDefender event
Defender-DeviceFileEventsanyFile activity
Defender-DeviceFileEventsFileCreatedFile created
Defender-DeviceImageLoadEventsanyImage load
Defender-DeviceNetworkEventsanyNetwork activity
Defender-DeviceNetworkEventsNetworkSignatureInspectedNetwork signature inspected
Defender-DeviceProcessEventsanyProcess activity
Defender-DeviceTvmSoftwareVulnerabilitiesanySoftware vulnerabilities on devices
ESFexecProcess Execution
Audit-CVEEvent ID 1Possible detection of CVE: PossibleDetectionOfCVE.
Sysmon-for-LinuxEvent ID 1Process Create
Windows-Server-Update-ServicesEvent ID 7053The WSUS administration console has encountered an unexpected error.

Authoring guide

These 129 rules share fields, values, and exclusions.

Fields filtered most (127 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType37eq 28, in 7, ne 2, starts_with 1exec, start, ProcessRollup2, connection_attempted, creation
process_name35eq 24, in 11, wildcard 4bash, dash, csh, curl, eqnedt32.exe
parent_process_name30eq 23, in 3, regex_match 3, wildcard 1foomatic-rip, java, (?i)EQNEDT32.EXE, 7zfm.exe, bandizip.exe
Image25ends_with 19, contains 2, is_not_null 2, eq 1, starts_with 1, wildcard 1\cmd.exe, \cscript.exe, \mshta.exe, /bash, \dfsvc.exe
event.type25eq 23, ne 3, in 1start, deletion, creation, process_started
host.os.type25eq 22, in 3
CommandLine20contains 13, wildcard 4, eq 2, match 2, regex_match 2, ends_with 1, is_not_null 1, is_null 1 -e , && echo, (?i).*mmc\.exe.*((Windows\s+\\\\System32)|(Windows\s+Syst..., * nc *, * ncat *
ParentImage17ends_with 14, eq 2, contains 1\winrar.exe, \winword.exe, c:\program files\internet explorer\iediagcmd.exe, /node, /rsync
process.args10eq 7, wildcard 4, starts_with 2, ends_with 1-c, .bat, .cmd, .com, --checkpoint-action=
TargetFilename8wildcard 5, contains 2, ends_with 1.cfg, .log, .txt, /*/sap.com/*/servlet_jsp/irj/root/*, /*/sap.com/*/servlet_jsp/irj/work/*
file.extension8eq 8exe, bat, cmd, com, dll
sourcetype8eq 8cisco:sfw:estreamer, stream:dns, stream:tcp
Action7eq 7, cross_field_compare 2Blocked, Matched, *, DvcAction, vulnerabilityAlert
CurrentDirectory6starts_with 3, eq 2, wildcard 1/var/opt/microsoft/scx/tmp, \\, *\sap.com*\servlet_jsp\irj\*, /*/sap.com*/servlet_jsp/irj/*, /u0?/
EventID6eq 67, 4688, 1, 22

Top indicator values (1207 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
221078
EventTypeeq
start
9391
EventTypeeq
exec
6576
EventTypeeq
connection_attempted
473
process_namein
bash
9202
process_namein
csh
9159
process_namein
dash
9170
process_namein
fish
9163
process_namein
ksh
9163
process_namein
sh
9197
process_namein
tcsh
9156
process_namein
zsh
9196
sourcetypeeq
cisco:sfw:estreamer
732
EventTypein
exec
6201
EventTypein
ProcessRollup2
5117
EventTypein
start
5163
Imageends_with
\cmd.exe
6130
Imageends_with
\powershell.exe
6179
Imageends_with
\pwsh.exe
6165
Imageends_with
\cscript.exe
472
Imageends_with
\rundll32.exe
494
Imageends_with
\wscript.exe
474
file.extensioneq
exe
632
Actioneq
Blocked
45
Actioneq
Matched
45
Total_TransactionIdge
3
46
parent_process_nameeq
winrar.exe
415
process_nameeq
ipconfig.exe
410
process_nameeq
netsh.exe
421
process_namewildcard
curl
431

Exclusions (429 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.code_signature.trustedeq
true
5
Imagewildcard
?:\program files (x86)\*.exe
3
Imagewildcard
?:\program files\*.exe
3
dest_ipcidr_match
10.0.0.0/8
3
dest_ipcidr_match
127.0.0.0/8
3
dest_ipcidr_match
169.254.0.0/16
3
dest_ipcidr_match
172.16.0.0/12
3
dest_ipcidr_match
192.168.0.0/16
3
process_nameeq
rundll32.exe
3
CommandLinewildcard
*-sDEVICE=ps2write*
2
CommandLinewildcard
*/tmp/foomatic-*
2
CommandLinewildcard
*printf*
2
CommandLinewildcard
/bin/bash -c cat
2
CommandLinewildcard
/bin/bash -e -c cat
2
CommandLinewildcard
/bin/sh -e -c cat
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 35 rules

Elastic 51 rules

Splunk 16 rules

Kusto 24 rules

Panther 3 rules