1200KM / detection
T1203 Exploitation for Client Execution — Detection Rules
Detection workspace for T1203 Exploitation for Client Execution: 17 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Antivirus Exploitation Framework Detection · stable · critical · {"category":"antivirus"}
- Suspicious Download and Execute Pattern via Curl/Wget · experimental · high · {"category":"process_creation","product":"linux"}
- OMIGOD SCX RunAsProvider ExecuteScript · test · high · {"product":"linux","category":"process_creation"}
- OMIGOD SCX RunAsProvider ExecuteShellCommand · test · high · {"product":"linux","category":"process_creation"}
- Suspicious Invocation of Shell via Rsync · experimental · high · {"category":"process_creation","product":"linux"}
- Suspicious Browser Child Process - MacOS · test · medium · {"category":"process_creation","product":"macos"}
- Download From Suspicious TLD - Blacklist · test · low · {"category":"proxy"}
- Download From Suspicious TLD - Whitelist · test · low · {"category":"proxy"}
- Audit CVE Event · test · critical · {"product":"windows","service":"application"}
- Network Connection Initiated By Eqnedt32.EXE · test · high · {"category":"network_connection","product":"windows"}
- Office Application Initiated Network Connection To Non-Local IP · test · medium · {"category":"network_connection","product":"windows"}
- Suspicious ArcSOC.exe Child Process · experimental · high · {"category":"process_creation","product":"windows"}
- Suspicious HWP Sub Processes · test · high · {"category":"process_creation","product":"windows"}
- Java Running with Remote Debugging · test · medium · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Child Process of KeyScrambler.exe · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Spool Service Child Process · test · high · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Child Process Of WinRAR.EXE · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1203 Exploitation for Client Execution
MATCH(exploit_mitigation_block OR application_crash_signature) FOLLOWED_BY child_process_creation WITHIN 2m -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0287 Exploitation for Client Execution – cross-platform behavior chain (browser/Office/3rd-party apps)
AN0797 Analytic 0797
Cause→effect chain: (1) A client app (browser, Office, PDF/Flash/reader) experiences a crash/abnormal exit or loads from an unusual location, then (2) drops or modifies a file in user-writable paths, and/or (3) spawns an unexpected child (e.g., powershell/cmd/mshta/rundll32/wscript/installer), and (4) establishes outbound C2-like connections shortly after. Correlate application logs, file writes, process lineage, and network egress within a short window.
AN0798 Analytic 0798
Cause→effect chain: (1) Browser/Office/reader process logs crash/segfault or abnormal sandbox message, (2) new executable/script/write occurs in $HOME (Downloads, ~/.cache, /tmp), (3) unexpected child like curl/wget/bash/python opens network connections soon after.
AN0799 Analytic 0799
Cause→effect chain: (1) App crash/abnormal termination in unified logs for Safari/Chrome/Office/Preview, (2) new files/scripts in ~/Library, ~/Downloads, /private/var/folders/*, (3) unexpected child (osascript, zsh, bash, curl) spawned by those apps, (4) new outbound connections.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Axiom · G0001
- APT12 · G0005
- APT28 · G0007
- Darkhotel · G0012
- APT29 · G0016
- admin@338 · G0018
- APT3 · G0022
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Sandworm Team · G0034
- Dragonfly · G0035
- Patchwork · G0040
- OilRig · G0049
- APT32 · G0050
- BRONZE BUTLER · G0060
- TA459 · G0062
- APT33 · G0064
- Leviathan · G0065
- Elderwood · G0066
- APT37 · G0067
- MuddyWater · G0069
- Cobalt Group · G0080
- Tropic Trooper · G0081
- The White Company · G0089
- APT41 · G0096
- BlackTech · G0098
- Inception · G0100
- Sidewinder · G0121
- Higaisa · G0126
- Mustang Panda · G0129
- Tonto Team · G0131
- Transparent Tribe · G0134
- Andariel · G0138
- Confucius · G0142
- BITTER · G1002
- Ember Bear · G1003
- Aoqin Dragon · G1007
- EXOTIC LILY · G1011
- Saint Bear · G1031
- Sea Turtle · G1041
- UNC3886 · G1048
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.