Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0287 — Exploitation for Client Execution – cross-platform behavior chain (browser/Office/3rd-party apps)
DET0287

Exploitation for Client Execution – cross-platform behavior chain (browser/Office/3rd-party apps)

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN0797 Analytic 0797
Windows

Cause→effect chain: (1) A client app (browser, Office, PDF/Flash/reader) experiences a crash/abnormal exit or loads from an unusual location, then (2) drops or modifies a file in user-writable paths, and/or (3) spawns an unexpected child (e.g., powershell/cmd/mshta/rundll32/wscript/installer), and (4) establishes outbound C2-like connections shortly after. Correlate application logs, file writes, process lineage, and network egress within a short window.

WinEventLog:Application EventCode=1000 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=3, 22
[TimeWindow] Correlation window (e.g., 15m) between crash/write/child/network.
[HighRiskChildren] List of child processes that should rarely spawn from Office/browsers (powershell.exe, cmd.exe, wscript.exe, mshta.exe, rundll32.exe, regsvr32.exe, msiexec.exe, curl.exe).
[UserPaths] Writable paths to watch (Downloads, %TEMP%, %APPDATA%, OneDrive, Office startup folders).
[AllowedPlugins] Known add-ins/extensions and updater binaries to reduce noise.
[EgressAllowlist] Known update/CDN domains and proxy egress CIDRs for suppression.
AN0798 Analytic 0798
Linux

Cause→effect chain: (1) Browser/Office/reader process logs crash/segfault or abnormal sandbox message, (2) new executable/script/write occurs in $HOME (Downloads, ~/.cache, /tmp), (3) unexpected child like curl/wget/bash/python opens network connections soon after.

linux:syslog browser/office crash, segfault, abnormal termination auditd:SYSCALL open auditd:SYSCALL creat auditd:SYSCALL rename,chmod auditd:SYSCALL execve NetFlow:Flow new outbound connections from exploited process tree
[TimeWindow] 5–20m correlation window.
[UserPaths] HOME write targets: ~/Downloads, ~/.config/autostart, ~/.local/share, /tmp.
[HighRiskChildren] bash, sh, python, perl, node, curl, wget, socat, openssl, xxd.
[PackageUpdaters] Allow-list common updaters (snap, flatpak, packagekit) to reduce FP.
AN0799 Analytic 0799
macOS

Cause→effect chain: (1) App crash/abnormal termination in unified logs for Safari/Chrome/Office/Preview, (2) new files/scripts in ~/Library, ~/Downloads, /private/var/folders/*, (3) unexpected child (osascript, zsh, bash, curl) spawned by those apps, (4) new outbound connections.

macos:unifiedlog process crash, abort, code signing violations fs:fsevents create/write/rename under user-writable paths macos:osquery exec NSM:Connections new connections from exploited lineage
[TimeWindow] 10–30m correlation window.
[HighRiskChildren] osascript, bash, zsh, curl, python, pbpaste/pbcopy, open -a Terminal.
[UserPaths] ~/Library/LaunchAgents, ~/Library/Containers/*/Data, /private/var/folders/*.
[QuarantineBypass] Flag files with missing com.apple.quarantine extended attribute when sourced from internet.

Detected Techniques

1

Details

MITRE ID
DET0287
STIX ID
x-mitre-detection-strategy--1894c2d7-ce4f-4cfd-8644-decb1e14f0c5
Analytics
3
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.