MITRE ATT&CK technique
Exploitation for Client Execution detection rulesT1203
Exploitation for Client Execution (T1203) is a MITRE ATT&CK technique in the Execution tactic. This page lists the 35 community-maintained Sigma detection rules in the library mapped to T1203 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, linux, zeek.
Antivirus - APT Malware Signature
criticalDetects a highly relevant Antivirus alert that reports APT malware. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
antivirus
Antivirus - Exploitation Framework Signature
criticalDetects a highly relevant Antivirus alert that reports an exploitation framework. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
antivirus
Antivirus - Remote Access Tools Signature
criticalDetects a highly relevant Antivirus alert that reports a remote access tool. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
antivirus
Audit CVE Event
criticalDetects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited. MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability. Unfortunately, that is about the only instance of CVEs being written to this log.
windows
CVE-2021-31979 CVE-2021-33771 Exploits
criticalDetects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
windows · registry_set
CVE-2021-31979 CVE-2021-33771 Exploits by Sourgum
criticalDetects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
windows · file_event
Droppers Exploiting CVE-2017-11882
criticalDetects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe
windows · process_creation
Exploit for CVE-2017-8759
criticalDetects Winword starting uncommon sub process csc.exe as used in exploits for CVE-2017-8759
windows · process_creation
CVE-2021-26858 Exchange Exploitation
highDetects possible successful exploitation for vulnerability described in CVE-2021-26858 by looking for creation of non-standard files on disk by Exchange Server’s Unified Messaging service which could indicate dropping web shells or other malicious content
windows · file_event
CVE-2023-38331 Exploitation Attempt - Suspicious WinRAR Child Process
highDetects exploitation attempt of CVE-2023-38331 (WinRAR before v6.23), where an attacker can leverage WinRAR to execute arbitrary commands and binaries.
windows · process_creation
Dfsvc.EXE Initiated Network Connection Over Uncommon Port
highDetects an initiated network connection over uncommon ports from "dfsvc.exe". A utility used to handled ClickOnce applications.
windows · network_connection
Exploitation Activity of CVE-2025-59287 - WSUS Deserialization
highDetects cast exceptions in Windows Server Update Services (WSUS) application logs that highly indicate exploitation attempts of CVE-2025-59287, a deserialization vulnerability in WSUS.
windows
Exploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Process
highDetects the creation of command-line interpreters (cmd.exe, powershell.exe) as child processes of Windows Server Update Services (WSUS) related process wsusservice.exe. This behavior is a key indicator of exploitation for the critical remote code execution vulnerability such as CVE-2025-59287, where attackers spawn shells to conduct reconnaissance and further post-exploitation activities.
windows · process_creation
Network Connection Initiated By Eqnedt32.EXE
highDetects network connections from the Equation Editor process "eqnedt32.exe".
windows · network_connection
OMIGOD HTTP No Authentication RCE - CVE-2021-38647
highDetects the exploitation of OMIGOD (CVE-2021-38647) which allows remote execute (RCE) commands as root with just a single unauthenticated HTTP request. Verify, successful, exploitation by viewing the HTTP client (request) body to see what was passed to the server (using PCAP). Within the client body is where the code execution would occur. Additionally, check the endpoint logs to see if suspicious commands or activity occurred within the timeframe of this HTTP request.
zeek
OMIGOD SCX RunAsProvider ExecuteScript
highRule to detect the use of the SCX RunAsProvider ExecuteScript to execute any UNIX/Linux script using the /bin/sh shell. Script being executed gets created as a temp file in /tmp folder with a scx* prefix. Then it is invoked from the following directory /etc/opt/microsoft/scx/conf/tmpdir/. The file in that directory has the same prefix scx*. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
linux · process_creation
OMIGOD SCX RunAsProvider ExecuteShellCommand
highRule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
linux · process_creation
Potential CVE-2021-26857 Exploitation Attempt
highDetects possible successful exploitation for vulnerability described in CVE-2021-26857 by looking for | abnormal subprocesses spawning by Exchange Server's Unified Messaging service
windows · process_creation
Potential Exploitation of CVE-2025-4427/4428 Ivanti EPMM Pre-Auth RCE
highDetects potential exploitation of a chained vulnerability attack targeting Ivanti EPMM 12.5.0.0. CVE-2025-4427 allows unauthenticated access to protected API endpoints via an authentication bypass, which can then be leveraged to trigger CVE-2025-4428 — a remote code execution vulnerability through template injection. This sequence enables unauthenticated remote code execution, significantly increasing the impact of exploitation.
webserver
Shai-Hulud Malicious Bun Execution
highDetects the execution of `bun_environment.js` via the Bun runtime, a behavior associated with the Shai-Hulud "Second Coming" NPM supply chain attack. The malware uses a `setup_bun.js` script to install the Bun runtime if not present, and then executes the malicious `bun_environment.js` payload.
windows · process_creation
Shai-Hulud Malicious Bun Execution - Linux
highDetects the execution of `bun_environment.js` via the Bun runtime, a behavior associated with the Shai-Hulud "Second Coming" NPM supply chain attack. The malware uses a `setup_bun.js` script to install the Bun runtime if not present, and then executes the malicious `bun_environment.js` payload.
linux · process_creation
Suspicious ArcSOC.exe Child Process
highDetects script interpreters, command-line tools, and similar suspicious child processes of ArcSOC.exe. ArcSOC.exe is the process name which hosts ArcGIS Server REST services. If an attacker compromises an ArcGIS Server system and uploads a malicious Server Object Extension (SOE), they can send crafted requests to the corresponding service endpoint and remotely execute code from the ArcSOC.exe process.
windows · process_creation
Suspicious Download and Execute Pattern via Curl/Wget
highDetects suspicious use of command-line tools such as curl or wget to download remote content - particularly scripts - into temporary directories (e.g., /dev/shm, /tmp), followed by immediate execution, indicating potential malicious activity. This pattern is commonly used by malicious scripts, stagers, or downloaders in fileless or multi-stage Linux attacks.
linux · process_creation
Suspicious HWP Sub Processes
highDetects suspicious Hangul Word Processor (Hanword) sub processes that could indicate an exploitation
windows · process_creation
Suspicious Invocation of Shell via Rsync
highDetects the execution of a shell as sub process of "rsync" without the expected command line flag "-e" being used, which could be an indication of exploitation as described in CVE-2024-12084. This behavior is commonly associated with attempts to execute arbitrary commands or escalate privileges, potentially leading to unauthorized access or further exploitation.
linux · process_creation
Suspicious Spool Service Child Process
highDetects suspicious print spool service (spoolsv.exe) child processes.
windows · process_creation
Dfsvc.EXE Network Connection To Non-Local IPs
mediumDetects network connections from "dfsvc.exe" used to handled ClickOnce applications to non-local IPs
windows · network_connection
Exploit for CVE-2017-0261
mediumDetects Winword starting uncommon sub process FLTLDR.exe as used in exploits for CVE-2017-0261 and CVE-2017-0262
windows · process_creation
Java Running with Remote Debugging
mediumDetects a JAVA process running with remote debugging allowing more than just localhost to connect
windows · process_creation
Office Application Initiated Network Connection To Non-Local IP
mediumDetects an office application (Word, Excel, PowerPoint) that initiate a network connection to a non-private IP addresses. This rule aims to detect traffic similar to one seen exploited in CVE-2021-42292. This rule will require an initial baseline and tuning that is specific to your organization.
windows · network_connection
Potentially Suspicious Child Process of KeyScrambler.exe
mediumDetects potentially suspicious child processes of KeyScrambler.exe
windows · process_creation
Potentially Suspicious Child Process Of WinRAR.EXE
mediumDetects potentially suspicious child processes of WinRAR.exe.
windows · process_creation
Suspicious Browser Child Process - MacOS
mediumDetects suspicious child processes spawned from browsers. This could be a result of a potential web browser exploitation.
macos · process_creation
Download From Suspicious TLD - Blacklist
lowDetects download of certain file types from hosts in suspicious TLDs
proxy
Download From Suspicious TLD - Whitelist
lowDetects executable downloads from suspicious remote systems
proxy