Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1203

T1203Exploitation for Client Execution

T1203 — Exploitation for Client Execution is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 46 detection use cases covering it and 21 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
46Use cases
21Articles
0Sub-techniques
1Tactic

Use cases covering this technique (46)

[WEEKLY] AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process Internal exploit · alerting DSΣPDDCS [WEEKLY] AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) Internal exploit · alerting DSΣPDDCS [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD Sunburst Correlation DLL and Network Event ESCU actions · alerting P Windows MSC EvilTwin Directory Path Manipulation ESCU actions · alerting P Windows Remote Image Load ESCU actions · hunting P Cisco Secure Firewall - Binary File Type Download ESCU actions · hunting P Cisco Secure Firewall - Blocked Connection ESCU actions · hunting P Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt ESCU actions · alerting P Cisco Secure Firewall - High Priority Intrusion Classification ESCU actions · alerting P Cisco Secure Firewall - Malware File Downloaded ESCU actions · hunting P Cisco Secure Firewall - Possibly Compromised Host ESCU actions · hunting P Cisco Secure Firewall - Repeated Blocked Connections ESCU actions · hunting P Detect Windows DNS SIGRed via Splunk Stream ESCU actions · alerting P Detect Windows DNS SIGRed via Zeek ESCU actions · alerting P [LLM] Ruflo/Node MCP bridge spawning interactive shell inside container (RufRoot RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Vulnerable Firefox exposed to CVE-2026-10702 JIT RCE (147 through 151.0.2) Bespoke exploit · alerting DSP [LLM] Outdated Tor Browser bundling vulnerable Firefox (CVE-2026-10702 exposure) Bespoke exploit · hunting DSPDDCS [LLM] Firefox/Tor renderer (content) process spawning an unexpected child — sandbox escape / RCE Bespoke exploit · alerting DSΣPDDCS [LLM] n8n/Node.js process spawning shell or recon utility (sandbox-escape RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Inbound HTML-attachment lure exploiting Zimbra XSS (CVE-2025-66376) Bespoke delivery · hunting DS [LLM] Unpatched Zimbra Collaboration exposed to CVE-2025-66376 (Void Blizzard target) Bespoke exploit · hunting DS [LLM] TidGi Desktop wiki worker spawning a command interpreter (TiddlyWiki startup-module RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] SiYuan Electron client spawns command interpreter (XSS-to-RCE via child_process) Bespoke exploit · alerting DSΣPDDCS [LLM] SiYuan Electron renderer (nodeIntegration) spawning shell/LOLBin child — XSS-to-RCE Bespoke exploit · alerting DSΣPDDCS [LLM] Joro native plugin RCE: joro process spawns interactive /bin/bash shell (CVE-2026-53649) Bespoke exploit · alerting DSΣPCS [LLM] Joro writes a native .so plugin: attacker plugin drop before restart (CVE-2026-53649) Bespoke install · hunting DSΣPCS [LLM] Langroid Python agent spawning shell/downloader child (os.system RCE) Bespoke exploit · hunting DSΣPCS [LLM] Langroid eval() exploit signature: __import__('os') / full_eval=True in cmdline or app logs Bespoke exploit · alerting DSΣPDDCS [LLM] Vulnerable Langroid package (<= 0.65.1) present on managed hosts Bespoke exploit · hunting DS [LLM] Gamaredon WinRAR CVE-2025-8088 ADS path-traversal dropping HTA/VBS into Startup folder Bespoke install · alerting DSΣPDDCS [LLM] Vulnerable WindowsCodecs.dll (CVE-2025-50165) present on endpoint Bespoke exploit · hunting DSΣPDDCS [LLM] Process crash with faulting module WindowsCodecs.dll (CVE-2025-50165 exploit attempt) Bespoke exploit · hunting DSPDDCS [LLM] WinRAR CVE-2025-8088 path traversal — payload dropped to user Startup folder Bespoke install · alerting DSΣPDDCS [LLM] Archive utility writing LNK/DLL/EXE to Windows Startup folder (RomCom CVE-2025-8088) Bespoke install · alerting DSΣP [LLM] Python interpreter executed from %TEMP% / Public — RomCom DLL side-load chain (CVE-2025-8088) Bespoke exploit · alerting DSΣP [LLM] GitHub Actions branch-name template injection — bash brace-expansion shell signature Bespoke exploit · alerting DSΣPDDCS [LLM] cups-browsed spawning foomatic-rip or shell child (CVE-2024-47177 RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Curl invoked with SOCKS5-hostname resolution (CVE-2023-38545 exploit precondition) Bespoke exploit · hunting DSΣPDDCS [LLM] Hosts exposed to libwebp heap overflow CVE-2023-4863 / CVE-2023-5129 (TVM) Bespoke weapon · alerting DSP [LLM] Unpatched libwebp-bundling apps in software inventory (Chrome, Electron, 1Password, ImageMagick, GIMP, ffmpeg) Bespoke weapon · hunting DSP [LLM] Vulnerable OpenSSL 3.0.0–3.0.6 exposure (CVE-2022-3602 / CVE-2022-3786, 'SpookySSL') Bespoke exploit · hunting DSP [LLM] Vulnerable Snyk CLI (< v1.996.0) present — CVE-2022-40764 command injection exposure Bespoke weapon · alerting DSP [LLM] Snyk CLI spawning a shell — CVE-2022-40764 command injection via go-plugin vendor.json Bespoke exploit · alerting DSΣPDDCS [LLM] Exposure hunt: CVE-2020-15999 FreeType overflow in Chromium/Electron/CefSharp software Bespoke exploit · hunting DSP [LLM] Grunt task-runner (node.exe) spawning a command shell — possible js-yaml load() ACE Bespoke exploit · hunting DSΣPDD

Articles citing this technique (21)