kevmap

TechniquesT1203 › AN0797

AN0797 Analytic 0797

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Cause→effect chain: (1) A client app (browser, Office, PDF/Flash/reader) experiences a crash/abnormal exit or loads from an unusual location, then (2) drops or modifies a file in user-writable paths, and/or (3) spawns an unexpected child (e.g., powershell/cmd/mshta/rundll32/wscript/installer), and (4) establishes outbound C2-like connections shortly after. Correlate application logs, file writes, process lineage, and network egress within a short window.</p>
Detects
T1203 Exploitation for Client Execution
Part of
DET0287 Exploitation for Client Execution – cross-platform behavior chain (browser/Office/3rd-party apps)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:ApplicationEventCode=1000DC0038 Application Log Content
WinEventLog:SysmonEventCode=11DC0039 File Creation
WinEventLog:SysmonEventCode=1DC0032 Process Creation
WinEventLog:SysmonEventCode=3, 22DC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TimeWindowCorrelation window (e.g., 15m) between crash/write/child/network.
HighRiskChildrenList of child processes that should rarely spawn from Office/browsers (powershell.exe, cmd.exe, wscript.exe, mshta.exe, rundll32.exe, regsvr32.exe, msiexec.exe, curl.exe).
UserPathsWritable paths to watch (Downloads, %TEMP%, %APPDATA%, OneDrive, Office startup folders).
AllowedPluginsKnown add-ins/extensions and updater binaries to reduce noise.
EgressAllowlistKnown update/CDN domains and proxy egress CIDRs for suppression.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2015-5119Adobe Flash PlayerMapped
CVE-2018-4939Adobe ColdFusionMapped
CVE-2021-21148Google Chromium V8Mapped
CVE-2021-21166Google ChromiumMapped
CVE-2021-21206Google Chromium BlinkMapped
CVE-2021-27059Microsoft OfficeMapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU)Mapped
CVE-2021-30554Google Chromium WebGLMapped
CVE-2021-37975Google Chromium V8Mapped
CVE-2021-39144XStream XStreamMapped
CVE-2022-20701Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2022-20703Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2022-23748Audinate Dante DiscoveryMapped
CVE-2022-41128Microsoft WindowsMapped
CVE-2022-43769Hitachi Vantara Pentaho Business Analytics (BA) ServerMapped
CVE-2023-21608Adobe Acrobat and ReaderMapped
CVE-2023-23397Microsoft OfficeMapped
CVE-2023-26369Adobe Acrobat and ReaderMapped
CVE-2023-34048VMware vCenter ServerMapped
CVE-2023-36844Juniper Junos OSMapped
CVE-2023-47565QNAP VioStor NVRMapped
CVE-2023-49897FXC AE1021, AE1021PEMapped
CVE-2024-11120GeoVision Multiple DevicesMapped
CVE-2024-26169Microsoft WindowsMapped
CVE-2024-45195Apache OFBizMapped
CVE-2024-5274Google Chromium V8Mapped
CVE-2025-24016Wazuh Wazuh ServerMapped
CVE-2025-24993Microsoft WindowsMapped
CVE-2025-27038Qualcomm Multiple ChipsetsMapped
CVE-2025-2783Google Chromium MojoMapped
CVE-2025-30397Microsoft WindowsMapped
CVE-2025-30406Gladinet CentreStackMapped
CVE-2025-31200Apple Multiple ProductsStale
CVE-2025-31201Apple Multiple ProductsStale
CVE-2025-3248Langflow LangflowMapped
CVE-2025-3935ConnectWise ScreenConnectMapped
CVE-2025-42999SAP NetWeaverMapped
CVE-2025-43200Apple Multiple ProductsMapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2025-5419Google Chromium V8Mapped
CVE-2025-6543Citrix NetScaler ADC and GatewayMapped
CVE-2025-6554Google Chromium V8Mapped
CVE-2025-6558Google ChromiumMapped