1200KM / simulation
T1203 Exploitation for Client Execution — Attack Simulation
Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution…
Technique description
Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution…
No compatible procedure was found in the pinned Atomic index. This is a support gap, not a finding of technical impossibility.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
No compatible documented candidate in the pinned snapshot. This is a support gap, not technical impossibility.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Axiom · G0001
- APT12 · G0005
- APT28 · G0007
- Darkhotel · G0012
- APT29 · G0016
- admin@338 · G0018
- APT3 · G0022
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Sandworm Team · G0034
- Dragonfly · G0035
- Patchwork · G0040
- OilRig · G0049
- APT32 · G0050
- BRONZE BUTLER · G0060
- TA459 · G0062
- APT33 · G0064
- Leviathan · G0065
- Elderwood · G0066
- APT37 · G0067
- MuddyWater · G0069
- Cobalt Group · G0080
- Tropic Trooper · G0081
- The White Company · G0089
- APT41 · G0096
- BlackTech · G0098
- Inception · G0100
- Sidewinder · G0121
- Higaisa · G0126
- Mustang Panda · G0129
- Tonto Team · G0131
- Transparent Tribe · G0134
- Andariel · G0138
- Confucius · G0142
- BITTER · G1002
- Ember Bear · G1003
- Aoqin Dragon · G1007
- EXOTIC LILY · G1011
- Saint Bear · G1031
- Sea Turtle · G1041
- UNC3886 · G1048
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.