Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1203

T1203Exploitation for Client Execution

T1203 — Exploitation for Client Execution is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 37 detection use cases covering it and 16 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
37Use cases
16Articles
0Sub-techniques
1Tactic

Use cases covering this technique (37)

[WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD Sunburst Correlation DLL and Network Event ESCU actions · alerting P Windows MSC EvilTwin Directory Path Manipulation ESCU actions · alerting P Windows Remote Image Load ESCU actions · hunting P Cisco Secure Firewall - Binary File Type Download ESCU actions · hunting P Cisco Secure Firewall - Blocked Connection ESCU actions · hunting P Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt ESCU actions · alerting P Cisco Secure Firewall - High Priority Intrusion Classification ESCU actions · alerting P Cisco Secure Firewall - Malware File Downloaded ESCU actions · hunting P Cisco Secure Firewall - Possibly Compromised Host ESCU actions · hunting P Cisco Secure Firewall - Repeated Blocked Connections ESCU actions · hunting P Detect Windows DNS SIGRed via Splunk Stream ESCU actions · alerting P Detect Windows DNS SIGRed via Zeek ESCU actions · alerting P [LLM] Shell/LOLBin spawned by LangGraph Python or Node runtime Bespoke install · alerting DSΣPDDCS [LLM] Endpoint exposure to CISA KEV adds: Chrome V8, Cisco SD-WAN Manager, Arista EOS (June 2026) Bespoke weapon · alerting DSP [LLM] Chrome browser spawning LOLBin children post-V8 sandbox-escape (CVE-2026-11645) Bespoke exploit · hunting DSΣPDDCS [LLM] DHCP Client svchost anomalous child process (CVE-2026-44815 post-exploit) Bespoke exploit · alerting DSΣPDDCS [LLM] Hosts missing June 2026 Patch Tuesday critical RCE/EoP fixes Bespoke weapon · hunting DSP [LLM] Outlook preview-pane Type Confusion exploit chain (Outlook → Word → LOLBin) Bespoke delivery · alerting DSΣPDDCS [LLM] mstsc.exe child process after outbound RDP to external server (RDC heap overflow) Bespoke exploit · alerting DSΣPDDCS [LLM] Unpatched Chrome vulnerable to CVE-2026-11645 and 2026 in-the-wild zero-days Bespoke exploit · hunting DSP [LLM] Chrome process executing with pre-fix V8 version (149.0.7827.<102) post-disclosure Bespoke exploit · hunting DSP [LLM] mcp-remote OAuth authorization_endpoint RCE (CVE-2025-6514) — node spawning shell Bespoke exploit · alerting DSΣPDDCS [LLM] Web service in container spawning interactive shell (Redis/nginx RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] SSH process spawned by Kopia invokes a shell child (ProxyCommand execution) Bespoke install · alerting DSPDDCS [LLM] Vulnerable Amazon Redshift JDBC Driver (CVE-2026-8178) inventory hunt — redshift-jdbc42 < 2.2.2 Bespoke recon · hunting DSP [LLM] CVE-2026-8178 exploit attempt: Redshift JDBC URL with class-loading parameter (socketFactory/sslfactory/sslhostnameverifier/sslpasswordcallb Bespoke exploit · alerting DSΣPDD [LLM] Vulnerable WindowsCodecs.dll (CVE-2025-50165) present on endpoint Bespoke exploit · hunting DSΣPDDCS [LLM] Process crash with faulting module WindowsCodecs.dll (CVE-2025-50165 exploit attempt) Bespoke exploit · hunting DSPDDCS [LLM] WinRAR CVE-2025-8088 path traversal — payload dropped to user Startup folder Bespoke install · alerting DSΣPDDCS [LLM] Archive utility writing LNK/DLL/EXE to Windows Startup folder (RomCom CVE-2025-8088) Bespoke install · alerting DSΣP [LLM] Python interpreter executed from %TEMP% / Public — RomCom DLL side-load chain (CVE-2025-8088) Bespoke exploit · alerting DSΣP [LLM] GitHub Actions branch-name template injection — bash brace-expansion shell signature Bespoke exploit · alerting DSΣPDDCS [LLM] cups-browsed spawning foomatic-rip or shell child (CVE-2024-47177 RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Curl invoked with SOCKS5-hostname resolution (CVE-2023-38545 exploit precondition) Bespoke exploit · hunting DSΣPDDCS [LLM] Hosts exposed to libwebp heap overflow CVE-2023-4863 / CVE-2023-5129 (TVM) Bespoke weapon · alerting DSP [LLM] Unpatched libwebp-bundling apps in software inventory (Chrome, Electron, 1Password, ImageMagick, GIMP, ffmpeg) Bespoke weapon · hunting DSP

Articles citing this technique (16)