Execution Detection Rules
The adversary is trying to run malicious code. Execution consists of techniques that result in adversary-controlled code running on a local or remote system. Techniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data. For example, an adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery.
df00tech ships 200 production-ready detection rules mapped to the Execution tactic (TA0002). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.
Unlock the full Pro package
Response playbooks, investigation guides and atomic tests for every technique — from £29/mo.
Execution detections (200)
- CVE-2008-0015 Microsoft Windows Video ActiveX Control Remote Code Execution (CVE-2008-0015)
- CVE-2009-0238 Microsoft Office Remote Code Execution (CVE-2009-0238)
- CVE-2009-0556 Microsoft Office PowerPoint Code Injection (CVE-2009-0556)
- CVE-2009-1537 Microsoft DirectX NULL Byte Overwrite Vulnerability (CVE-2009-1537)
- CVE-2009-3459 Adobe Acrobat and Reader Heap-Based Buffer Overflow (CVE-2009-3459)
- CVE-2010-0249 Microsoft Internet Explorer Use-After-Free Vulnerability (CVE-2010-0249)
- CVE-2010-0806 CVE-2010-0806 Microsoft Internet Explorer Use-After-Free Exploitation
- CVE-2012-1854 CVE-2012-1854 - Microsoft VBA Insecure Library Loading (DLL Hijacking)
- CVE-2018-4063 Sierra Wireless AirLink ALEOS Unrestricted File Upload Exploitation
- CVE-2020-9715 Adobe Acrobat Use-After-Free Exploitation (CVE-2020-9715)
- CVE-2021-26828 CVE-2021-26828: OpenPLC ScadaBR Unrestricted File Upload RCE
- CVE-2021-30952 CVE-2021-30952: Apple Multiple Products Integer Overflow Exploitation
- CVE-2022-0492 Linux Kernel cgroup v1 release_agent Privilege Escalation (CVE-2022-0492)
- CVE-2022-37055 CVE-2022-37055 D-Link Router Buffer Overflow Exploitation
- CVE-2022-48503 CVE-2022-48503 Apple Multiple Products Unspecified Vulnerability Exploitation
- CVE-2023-21529 Microsoft Exchange Server Deserialization of Untrusted Data (CVE-2023-21529)
- CVE-2023-36424 CVE-2023-36424 - Microsoft Windows Out-of-Bounds Read Exploitation
- CVE-2023-41974 Apple iOS/iPadOS Use-After-Free Exploitation (CVE-2023-41974)
- CVE-2023-43000 Apple Multiple Products Use-After-Free Vulnerability (CVE-2023-43000)
- CVE-2024-1708 ConnectWise ScreenConnect Path Traversal (CVE-2024-1708)
- CVE-2024-3400 Palo Alto PAN-OS GlobalProtect Command Injection (CVE-2024-3400)
- CVE-2024-7399 Samsung MagicINFO 9 Server Path Traversal and Arbitrary File Upload
- CVE-2024-7694 TeamT5 ThreatSonar Anti-Ransomware Unrestricted File Upload (CVE-2024-7694)
- CVE-2024-21182 Oracle WebLogic Server CVE-2024-21182 Exploitation Attempt
- CVE-2024-21887 Ivanti Connect Secure Authenticated Command Injection (CVE-2024-21887)
- CVE-2024-23897 CVE-2024-23897: Jenkins Arbitrary File Read via CLI Argument Parser (Pre-Auth RCE Chain)
- CVE-2024-30078 CVE-2024-30078: Windows Wi-Fi Driver Remote Code Execution via Adjacent Network
- CVE-2024-37079 VMware vCenter Server Out-of-bounds Write (CVE-2024-37079)
- CVE-2024-38112 CVE-2024-38112 - Windows MSHTML Spoofing via .url File Phishing (Void Banshee)
- CVE-2025-2749 Kentico Xperience Path Traversal and Arbitrary File Upload (CVE-2025-2749)
- CVE-2025-6204 CVE-2025-6204 — Dassault Systèmes DELMIA Apriso Code Injection
- CVE-2025-6218 CVE-2025-6218: RARLAB WinRAR Path Traversal Exploitation
- CVE-2025-9242 WatchGuard Firebox Out-of-Bounds Write Exploitation (CVE-2025-9242)
- CVE-2025-11953 React Native Community CLI OS Command Injection (CVE-2025-11953)
- CVE-2025-13223 Google Chromium V8 Type Confusion Exploitation (CVE-2025-13223)
- CVE-2025-14174 CVE-2025-14174: Google Chromium Out of Bounds Memory Access Exploitation
- CVE-2025-14611 Gladinet CentreStack and Triofox Hard-Coded Cryptographic Key Exploitation
- CVE-2025-14733 CVE-2025-14733: WatchGuard Firebox Out-of-Bounds Write Exploitation
- CVE-2025-15556 Notepad++ Download of Code Without Integrity Check (CVE-2025-15556)
- CVE-2025-21298 CVE-2025-21298: Windows OLE RCE via Malicious RTF Document
- CVE-2025-24893 CVE-2025-24893 XWiki Platform Eval Injection Exploitation
- CVE-2025-26399 SolarWinds Web Help Desk Deserialization of Untrusted Data (CVE-2025-26399)
- CVE-2025-31277 Apple Multiple Products Buffer Overflow Exploitation (CVE-2025-31277)
- CVE-2025-32432 CVE-2025-32432: Craft CMS Remote Code Injection
- CVE-2025-37164 HPE OneView Code Injection Exploitation (CVE-2025-37164)
- CVE-2025-40551 CVE-2025-40551 — SolarWinds Web Help Desk Deserialization RCE
- CVE-2025-43510 Apple Multiple Products Improper Locking Vulnerability (CVE-2025-43510)
- CVE-2025-43520 Apple Multiple Products Classic Buffer Overflow Exploitation (CVE-2025-43520)
- CVE-2025-43529 Apple WebKit Use-After-Free Exploitation Attempt (CVE-2025-43529)
- CVE-2025-48703 CVE-2025-48703 - CWP Control Web Panel OS Command Injection
- CVE-2025-49113 RoundCube Webmail Deserialization of Untrusted Data (CVE-2025-49113)
- CVE-2025-52691 SmarterMail Unrestricted File Upload Exploitation (CVE-2025-52691)
- CVE-2025-53521 F5 BIG-IP Stack-Based Buffer Overflow Exploitation (CVE-2025-53521)
- CVE-2025-54068 Laravel Livewire Code Injection (CVE-2025-54068)
- CVE-2025-54236 Adobe Commerce / Magento Improper Input Validation (CVE-2025-54236)
- CVE-2025-54313 Prettier eslint-config-prettier Embedded Malicious Code (CVE-2025-54313)
- CVE-2025-55182 CVE-2025-55182 — Meta React Server Components Remote Code Execution
- CVE-2025-58034 Fortinet FortiWeb OS Command Injection (CVE-2025-58034)
- CVE-2025-58048 CVE-2025-58048: Paymenter Remote Code Execution via Unrestricted File Upload
- CVE-2025-59287 Microsoft WSUS Deserialization of Untrusted Data (CVE-2025-59287)
- CVE-2025-59374 ASUS Live Update Embedded Malicious Code (CVE-2025-59374)
- CVE-2025-62215 CVE-2025-62215 Microsoft Windows Race Condition Exploitation
- CVE-2025-62221 CVE-2025-62221 Microsoft Windows Use After Free Exploitation
- CVE-2025-64328 Sangoma FreePBX OS Command Injection (CVE-2025-64328)
- CVE-2025-66644 Array Networks ArrayOS AG OS Command Injection (CVE-2025-66644)
- CVE-2025-67038 CVE-2025-67038 Lantronix EDS5000 Code Injection Exploitation
- CVE-2025-68461 RoundCube Webmail Cross-Site Scripting (XSS) Exploitation Attempt
- CVE-2025-68613 n8n Improper Control of Dynamically-Managed Code Resources (CVE-2025-68613)
- CVE-2025-68645 Synacor Zimbra Collaboration Suite PHP Remote File Inclusion (CVE-2025-68645)
- CVE-2025-68670 xrdp Unauthenticated Stack Buffer Overflow via RDP Connection Sequence (CVE-2025-68670)
- CVE-2026-0300 Palo Alto Networks PAN-OS Out-of-bounds Write (CVE-2026-0300)
- CVE-2026-0755 CVE-2026-0755: gemini-mcp-tool OS Command Injection and File Exfiltration via Prompt Quoting
- CVE-2026-1281 CVE-2026-1281 — Ivanti EPMM Code Injection Exploitation
- CVE-2026-1340 Ivanti EPMM Code Injection Exploitation (CVE-2026-1340)
- CVE-2026-1731 BeyondTrust Remote Support Pre-Auth RCE (CVE-2026-1731)
- CVE-2026-2441 CVE-2026-2441: Google Chromium CSS Use-After-Free Exploitation
- CVE-2026-3502 TrueConf Client Download of Code Without Integrity Check (CVE-2026-3502)
- CVE-2026-3909 Google Skia Out-of-Bounds Write (CVE-2026-3909)
- CVE-2026-3910 CVE-2026-3910: Google Chromium V8 Memory Buffer Bounds Violation
- CVE-2026-5281 CVE-2026-5281 — Google Dawn Use-After-Free Exploitation
- CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code (CVE-2026-8398)
- CVE-2026-10520 Ivanti Sentry OS Command Injection Exploitation (CVE-2026-10520)
- CVE-2026-11645 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability (CVE-2026-11645)
- CVE-2026-12569 CVE-2026-12569 - PTC Windchill and FlexPLM Improper Input Validation / Unsafe Deserialization
- CVE-2026-15410 SonicWall SMA1000 Code Injection Exploitation (CVE-2026-15410)
- CVE-2026-20045 CVE-2026-20045: Cisco Unified Communications Manager Code Injection
- CVE-2026-20131 Cisco FMC/SCC Deserialization RCE Exploitation (CVE-2026-20131)
- CVE-2026-20700 Apple Multiple Products Buffer Overflow Exploitation (CVE-2026-20700)
- CVE-2026-20963 Microsoft SharePoint Deserialization of Untrusted Data (CVE-2026-20963)
- CVE-2026-21510 CVE-2026-21510: Microsoft Windows Shell Protection Mechanism Failure
- CVE-2026-21513 CVE-2026-21513 — Microsoft MSHTML Framework Protection Mechanism Failure
- CVE-2026-21514 Microsoft Office Word Reliance on Untrusted Inputs in Security Decision (CVE-2026-21514)
- CVE-2026-21519 Microsoft Windows Type Confusion Vulnerability (CVE-2026-21519)
- CVE-2026-21525 CVE-2026-21525 - Microsoft Windows NULL Pointer Dereference Exploitation
- CVE-2026-22719 CVE-2026-22719: VMware Aria Operations Command Injection
- CVE-2026-25089 Fortinet FortiSandbox OS Command Injection (CVE-2026-25089)
- CVE-2026-25108 Soliton FileZen OS Command Injection Exploitation (CVE-2026-25108)
- CVE-2026-30120 Remotion RCE via Code Injection (CVE-2026-30120)
- CVE-2026-32201 Microsoft SharePoint Server Improper Input Validation (CVE-2026-32201)
- CVE-2026-32202 CVE-2026-32202 Microsoft Windows Protection Mechanism Failure
- CVE-2026-33017 CVE-2026-33017: Langflow Code Injection Vulnerability
- CVE-2026-33634 Aquasecurity Trivy Embedded Malicious Code (CVE-2026-33634)
- CVE-2026-33646 CVE-2026-33646: Mise Arbitrary Code Execution via Tera Template Injection in .tool-versions
- CVE-2026-34197 Apache ActiveMQ Improper Input Validation (CVE-2026-34197)
- CVE-2026-34621 Adobe Acrobat and Reader Prototype Pollution Vulnerability (CVE-2026-34621)
- CVE-2026-34910 Ubiquiti UniFi OS Improper Input Validation Vulnerability (CVE-2026-34910)
- CVE-2026-39808 Fortinet FortiSandbox OS Command Injection (CVE-2026-39808)
- CVE-2026-39987 Marimo Remote Code Execution via Missing Authentication (CVE-2026-39987)
- CVE-2026-42271 BerriAI LiteLLM Command Injection (CVE-2026-42271)
- CVE-2026-42897 Microsoft Exchange Server Cross-Site Scripting (XSS) Exploitation
- CVE-2026-44179 CVE-2026-44179: XWiki Pro Macros RCE via Excerpt-Include Macro
- CVE-2026-45247 Mirasvit Full Page Cache Warmer Deserialization RCE (CVE-2026-45247)
- CVE-2026-45321 TanStack Router Unspecified Vulnerability Exploitation
- CVE-2026-45579 DIRAC RequestManager eval() Remote Code Execution (CVE-2026-45579)
- CVE-2026-45659 CVE-2026-45659 Microsoft SharePoint Server Deserialization RCE
- CVE-2026-47103 python-statemachine SCXML <data expr> Eval Injection (CVE-2026-47103)
- CVE-2026-47137 CVE-2026-47137 — vm2 Sandbox Escape via nesting:true Bypass (RCE)
- CVE-2026-47140 CVE-2026-47140 — vm2 Builtin Denylist Bypass via process/inspector Leads to Host RCE
- CVE-2026-47208 CVE-2026-47208: vm2 Sandbox Breakout via Promise Species
- CVE-2026-47210 vm2 Sandbox Escape via JSPI-backed Promise .finally() Species Bypass
- CVE-2026-47391 CVE-2026-47391: PraisonAI Unauthenticated A2A LLM eval() Remote Code Execution
- CVE-2026-47392 PraisonAI Sandbox Escape via print.__self__ Builtins Leak in execute_code
- CVE-2026-47428 CVE-2026-47428: Vitest Browser Mode XSS via Unsanitized otelCarrier Query Parameter
- CVE-2026-47429 CVE-2026-47429: Vitest UI Server Arbitrary File Read and Execution
- CVE-2026-47668 CVE-2026-47668: DbGate Unauthenticated RCE via JSON Script Runner
- CVE-2026-48027 Nx Console Embedded Malicious Code Execution (CVE-2026-48027)
- CVE-2026-48030 Pheditor OS Command Injection via Unsanitized 'dir' Parameter (CVE-2026-48030)
- CVE-2026-48062 CVE-2026-48062: CodeIgniter4 File Upload Extension Validation Bypass (ext_in Rule)
- CVE-2026-48750 Incus exec-output Symlink Arbitrary File Write on Host (CVE-2026-48750)
- CVE-2026-48751 CVE-2026-48751: Incus Restricted Project Bypass Leading to Arbitrary Command Execution
- CVE-2026-48755 Incus Argument Injection in Backup Compression Algorithm (CVE-2026-48755)
- CVE-2026-48908 CVE-2026-48908 - JoomShaper SP Page Builder Unrestricted File Upload
- CVE-2026-48939 iCagenda Unrestricted File Upload Exploitation (CVE-2026-48939)
- CVE-2026-49252 Deepstream Server Prototype Pollution (CVE-2026-49252)
- CVE-2026-49980 Rclone RCD Unauthenticated Command Execution via Inline Remote Instantiation (CVE-2026-49980)
- CVE-2026-50551 SiYuan Attribute View Asset Cell Stored XSS to RCE (CVE-2026-50551)
- CVE-2026-52806 CVE-2026-52806: Gogs RCE via git rebase --exec Argument Injection in PR Merge
- CVE-2026-52813 Gogs Path Traversal in Organization Name Leading to RCE via Git Hooks
- CVE-2026-52831 Nuclio Cron Trigger Header/Body Command Injection (CVE-2026-52831)
- CVE-2026-53633 CVE-2026-53633: Vitest Browser Mode API RCE via CDP Proxy and Config Overwrite
- CVE-2026-53753 Crawl4AI AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE
- CVE-2026-54051 CVE-2026-54051: network-ai npm Package OS Command Injection
- CVE-2026-54159 PrestaShop ps_facetedsearch PHP Object Injection Leading to Unauthenticated RCE (CVE-2026-54159)
- CVE-2026-54769 CVE-2026-54769: Langroid TableChatAgent Sandbox Escape via eval() RCE
- CVE-2026-56164 Microsoft SharePoint Server Missing Authentication for Critical Function (CVE-2026-56164)
- CVE-2026-56266 Crawl4AI Docker API Multiple Critical Vulnerabilities (File Write, SSRF, Auth Bypass, XSS, JS Execution)
- CVE-2026-56291 Balbooa Forms Unrestricted File Upload Exploitation (CVE-2026-56291)
- CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Exploitation (CVE-2026-58644)
- T1047 Windows Management Instrumentation
- T1053 Scheduled Task/Job
- T1053.002 At
- T1053.003 Cron
- T1053.005 Scheduled Task
- T1053.006 Systemd Timers
- T1053.007 Container Orchestration Job
- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1059.002 AppleScript
- T1059.003 Windows Command Shell
- T1059.004 Unix Shell
- T1059.005 Visual Basic
- T1059.006 Python
- T1059.007 JavaScript
- T1059.008 Network Device CLI
- T1059.009 Cloud API
- T1059.010 AutoHotKey & AutoIT
- T1059.011 Lua
- T1059.012 Hypervisor CLI
- T1059.013 Container CLI/API
- T1061 Graphical User Interface
- T1064 Scripting
- T1072 Software Deployment Tools
- T1106 Native API
- T1129 Shared Modules
- T1153 Source
- T1175 Component Object Model and Distributed COM
- T1203 Exploitation for Client Execution
- T1204 User Execution
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1204.003 Malicious Image
- T1204.004 Malicious Copy and Paste
- T1204.005 Malicious Library
- T1559 Inter-Process Communication
- T1559.001 Component Object Model
- T1559.002 Dynamic Data Exchange
- T1559.003 XPC Services
- T1569 System Services
- T1569.001 Launchctl
- T1569.002 Service Execution
- T1569.003 Systemctl
- T1609 Container Administration Command
- T1610 Deploy Container
- T1648 Serverless Execution
- T1651 Cloud Administration Command
- T1674 Input Injection
- T1675 ESXi Administration Command
- T1677 Poisoned Pipeline Execution
- THREAT-InitialAccess-PhishingMacro Phishing Document Macro Execution and Initial Access
- THREAT-LateralMovement-SMBPsExec Lateral Movement via SMB and PsExec-Style Remote Execution
Related tactics
266 detections
225 detections