Exploitation for Client Execution T1203
Tactic: Execution
Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.
Events covered
29 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 129 rules share fields, values, and exclusions.
Fields filtered most (127 distinct)
These fields appear most often in rule filters.
Top indicator values (1207 distinct)
These values appear most often in rule predicates.
Exclusions (429 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 35 rules
- Antivirus - APT Malware Signature
- Antivirus - Exploitation Framework Signature
- Antivirus - Remote Access Tools Signature
- Audit CVE Event
- CVE-2021-26858 Exchange Exploitation
- CVE-2021-31979 CVE-2021-33771 Exploits
- CVE-2021-31979 CVE-2021-33771 Exploits by Sourgum
- CVE-2023-38331 Exploitation Attempt - Suspicious WinRAR Child Process
- Dfsvc.EXE Initiated Network Connection Over Uncommon Port
- Dfsvc.EXE Network Connection To Non-Local IPs
- Download From Suspicious TLD - Blacklist
- Download From Suspicious TLD - Whitelist
- Droppers Exploiting CVE-2017-11882
- Exploit for CVE-2017-0261
- Exploit for CVE-2017-8759
- Exploitation Activity of CVE-2025-59287 - WSUS Deserialization
- Exploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Process
- Java Running with Remote Debugging
- Network Connection Initiated By Eqnedt32.EXE
- Office Application Initiated Network Connection To Non-Local IP
- OMIGOD HTTP No Authentication RCE - CVE-2021-38647
- OMIGOD SCX RunAsProvider ExecuteScript
- OMIGOD SCX RunAsProvider ExecuteShellCommand
- Potential CVE-2021-26857 Exploitation Attempt
- Potential Exploitation of CVE-2025-4427/4428 Ivanti EPMM Pre-Auth RCE
- Potentially Suspicious Child Process of KeyScrambler.exe
- Potentially Suspicious Child Process Of WinRAR.EXE
- Shai-Hulud Malicious Bun Execution
- Shai-Hulud Malicious Bun Execution - Linux
- Suspicious ArcSOC.exe Child Process
- Suspicious Browser Child Process - MacOS
- Suspicious Download and Execute Pattern via Curl/Wget
- Suspicious HWP Sub Processes
- Suspicious Invocation of Shell via Rsync
- Suspicious Spool Service Child Process
Elastic 51 rules
- Anomalous Windows Process Creation
- Creation of SettingContent-ms Files
- Cupsd or Foomatic-rip Shell Execution
- Execution from a Remote Working Directory
- Execution of File Written or Modified by Microsoft Equation Editor
- Execution of File Written or Modified by Microsoft Office
- Exploit - Detected - Elastic Endgame
- Exploit - Prevented - Elastic Endgame
- File Creation by Cups or Foomatic-rip Child
- Microsoft Equation Editor Child Process
- Multiple DHCP Servers Responding to the Same Transaction
- Network Connection by Cups or Foomatic-rip Child
- Potential Browser Exploit via Fake RPC Messages
- Potential CVE-2024-21412 Exploitation
- Potential CVE-2025-33053 Exploitation
- Potential CVE-2025-33053 Exploitation
- Potential Execution via Archive Exploit
- Potential Execution via Foxmail Exploitation
- Potential Execution via WinRAR Exploitation
- Potential Foxmail Exploitation
- Potential Git CVE-2025-48384 Exploitation
- Potential Git CVE-2025-48384 Exploitation
- Potential JAVA/JNDI Exploitation Attempt
- Potential Microsoft Outlook Remote Code Execution
- Potential Notepad Markdown RCE Exploitation
- Potential Remote Code Execution via Langflow
- Potential SAP NetWeaver Exploitation
- Potential SAP NetWeaver WebShell Creation
- Potential Shell via Wildcard Injection Detected
- Potential Shellcode Injection by a Browser Process
- Potential WinRAR CVE-2023-38831 Exploitation
- Printer User (lp) Shell Execution
- Segfault Detected
- Segfault from Sensitive Process Detected
- Shell Execution via Java Parent Process
- Suspicious Browser Child Process
- Suspicious Communication App Child Process
- Suspicious Execution from Foomatic-rip or Cupsd Parent
- Suspicious Execution from INET Cache
- Suspicious macOS MS Office Child Process
- Suspicious Microsoft Office Embedded Object
- Suspicious MS Office Child Process
- Suspicious Network Connection from Microsoft Equation Editor
- Suspicious Outlook Child Process
- Suspicious PDF Reader Child Process
- Suspicious Shell Execution via Java Application
- Suspicious VirtualProtect via Jscript9 from Internet Explorer
- Suspicious Zoom Child Process
- Unusual Executable File Creation by a System Critical Process
- WPS Office Exploit via DLL Hijack
- WPS Office Exploitation via DLL Hijack
Splunk 16 rules
- Abuse EQNEDT32.EXE (Sysmon)
- Abuse EQNEDT32.EXE (Windows Event Log)
- Cisco Secure Firewall - Binary File Type Download
- Cisco Secure Firewall - Blocked Connection
- Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt
- Cisco Secure Firewall - High Priority Intrusion Classification
- Cisco Secure Firewall - Malware File Downloaded
- Cisco Secure Firewall - Possibly Compromised Host
- Cisco Secure Firewall - Repeated Blocked Connections
- Detect Windows DNS SIGRed via Splunk Stream
- Detect Windows DNS SIGRed via Zeek
- Potential Follina_DogWalk Activity - mdst.exe (Sysmon)
- Sunburst Correlation DLL and Network Event
- Suspicious process Spawned by Java (Windows Event Log)
- Windows MSC EvilTwin Directory Path Manipulation
- Windows Remote Image Load
Kusto 24 rules
- AFD WAF - Code Injection
- AFD WAF - Path Traversal Attack
- Antivirus Detected an Infected File
- App Gateway WAF - Scanner Detection
- App Gateway WAF - XSS Detection
- App GW WAF - Code Injection
- App GW WAF - Path Traversal Attack
- Application Gateway WAF - XSS Detection
- BitSight - compromised systems detected
- BitSight - diligence risk category detected
- Detect CVE exploits on network for which a device is vulnerable
- Detect port misuse by anomaly based detection (ASIM Network Session schema)
- Detect port misuse by static threshold (ASIM Network Session schema)
- Detect web requests to potentially harmful files (ASIM Web Session)
- Execution of software vulnerable to webp buffer overflow of CVE-2023-4863
- Front Door Premium WAF - XSS Detection
- GitHub Security Vulnerability in Repository
- Malformed user agent
- New UserAgent observed in last 24 hours
- Office Apps Launching Wscipt
- PE file dropped in Color Profile Folder
- Prestige ransomware IOCs Oct 2022
- Vulnerable Machines related to log4j CVE-2021-44228
- Vulnerable Machines related to OMIGOD CVE-2021-38647