T1203 Exploitation for Client Execution
Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Antivirus - Exploitation Framework Signaturecriticalstable · antivirus
- Droppers Exploiting CVE-2017-11882criticalstable · windows
- Audit CVE Eventcriticaltest · windows
- CVE-2021-31979 CVE-2021-33771 Exploitscriticaltest · windows
- CVE-2021-31979 CVE-2021-33771 Exploits by Sourgumcriticaltest · windows
- Exploit for CVE-2017-8759criticaltest · windows
- Antivirus - APT Malware Signaturecriticalexperimental · antivirus
- Antivirus - Remote Access Tools Signaturecriticalexperimental · antivirus
- OMIGOD HTTP No Authentication RCE - CVE-2021-38647highstable · zeek
- Potential CVE-2021-26857 Exploitation Attempthighstable · windows
- CVE-2021-26858 Exchange Exploitationhightest · windows
- CVE-2023-38331 Exploitation Attempt - Suspicious WinRAR Child Processhightest · windows
- Network Connection Initiated By Eqnedt32.EXEhightest · windows
- OMIGOD SCX RunAsProvider ExecuteScripthightest · linux
- OMIGOD SCX RunAsProvider ExecuteShellCommandhightest · linux
- Suspicious HWP Sub Processeshightest · windows
- Suspicious Spool Service Child Processhightest · windows
- Exploitation Activity of CVE-2025-59287 - WSUS Deserializationhighexperimental · windows
- Exploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Processhighexperimental · windows
- Potential Exploitation of CVE-2025-4427/4428 Ivanti EPMM Pre-Auth RCEhighexperimental · webserver
- Shai-Hulud Malicious Bun Executionhighexperimental · windows
- Shai-Hulud Malicious Bun Execution - Linuxhighexperimental · linux
- Suspicious ArcSOC.exe Child Processhighexperimental · windows
- Suspicious Download and Execute Pattern via Curl/Wgethighexperimental · linux
- Suspicious Invocation of Shell via Rsynchighexperimental · linux
Mostrando 25 de 31.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.