kevmap

TechniquesT1203 › AN0798

AN0798 Analytic 0798

Linux · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Cause→effect chain: (1) Browser/Office/reader process logs crash/segfault or abnormal sandbox message, (2) new executable/script/write occurs in $HOME (Downloads, ~/.cache, /tmp), (3) unexpected child like curl/wget/bash/python opens network connections soon after.</p>
Detects
T1203 Exploitation for Client Execution
Part of
DET0287 Exploitation for Client Execution – cross-platform behavior chain (browser/Office/3rd-party apps)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
linux:syslogbrowser/office crash, segfault, abnormal terminationDC0038 Application Log Content
auditd:SYSCALLopenDC0055 File Access
auditd:SYSCALLcreatDC0039 File Creation
auditd:SYSCALLrename,chmodDC0061 File Modification
auditd:SYSCALLexecveDC0032 Process Creation
NetFlow:Flownew outbound connections from exploited process treeDC0078 Network Traffic Flow

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TimeWindow5–20m correlation window.
UserPathsHOME write targets: ~/Downloads, ~/.config/autostart, ~/.local/share, /tmp.
HighRiskChildrenbash, sh, python, perl, node, curl, wget, socat, openssl, xxd.
PackageUpdatersAllow-list common updaters (snap, flatpak, packagekit) to reduce FP.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2015-5119Adobe Flash PlayerMapped
CVE-2018-4939Adobe ColdFusionMapped
CVE-2021-21148Google Chromium V8Mapped
CVE-2021-21166Google ChromiumMapped
CVE-2021-21206Google Chromium BlinkMapped
CVE-2021-27059Microsoft OfficeMapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU)Mapped
CVE-2021-30554Google Chromium WebGLMapped
CVE-2021-37975Google Chromium V8Mapped
CVE-2021-39144XStream XStreamMapped
CVE-2022-20701Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2022-20703Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2022-23748Audinate Dante DiscoveryMapped
CVE-2022-41128Microsoft WindowsMapped
CVE-2022-43769Hitachi Vantara Pentaho Business Analytics (BA) ServerMapped
CVE-2023-21608Adobe Acrobat and ReaderMapped
CVE-2023-23397Microsoft OfficeMapped
CVE-2023-26369Adobe Acrobat and ReaderMapped
CVE-2023-34048VMware vCenter ServerMapped
CVE-2023-36844Juniper Junos OSMapped
CVE-2023-47565QNAP VioStor NVRMapped
CVE-2023-49897FXC AE1021, AE1021PEMapped
CVE-2024-11120GeoVision Multiple DevicesMapped
CVE-2024-26169Microsoft WindowsMapped
CVE-2024-45195Apache OFBizMapped
CVE-2024-5274Google Chromium V8Mapped
CVE-2025-24016Wazuh Wazuh ServerMapped
CVE-2025-24993Microsoft WindowsMapped
CVE-2025-27038Qualcomm Multiple ChipsetsMapped
CVE-2025-2783Google Chromium MojoMapped
CVE-2025-30397Microsoft WindowsMapped
CVE-2025-30406Gladinet CentreStackMapped
CVE-2025-31200Apple Multiple ProductsStale
CVE-2025-31201Apple Multiple ProductsStale
CVE-2025-3248Langflow LangflowMapped
CVE-2025-3935ConnectWise ScreenConnectMapped
CVE-2025-42999SAP NetWeaverMapped
CVE-2025-43200Apple Multiple ProductsMapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2025-5419Google Chromium V8Mapped
CVE-2025-6543Citrix NetScaler ADC and GatewayMapped
CVE-2025-6554Google Chromium V8Mapped
CVE-2025-6558Google ChromiumMapped