Cross-source coverage

T1216 / ATT&CK

System Script Proxy Execution

25 rules · 23 families across 5 sources.

From MITRE ATT&CK 19.2

Adversaries may use trusted scripts, often signed with certificates, to proxy the execution of malicious files. Several Microsoft signed scripts that have been downloaded from Microsoft or are default on Windows installations can be used to proxy execution of other files. This behavior may be abused by adversaries to execute malicious files that could bypass application control and signature validation on systems.

Tactics
Stealth
Platforms
Windows
Telemetry
WinEventLog:SysmonWinEventLog:PowerShell

How MITRE says to detect it DET0466

Detection of Script-Based Proxy Execution via Signed Microsoft Utilities

Windows Analytic 1288

Execution of Microsoft-signed scripts (e.g., pubprn.vbs, installutil.exe, wscript.exe, cscript.exe) used to proxy execution of untrusted or external binaries. Behavior is detected through command-line process lineage, child process spawning, and unsigned payload execution from signed parent.

  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106
  • WinEventLog:Sysmon EventCode=7
  • WinEventLog:Sysmon EventCode=10
  • WinEventLog:Sysmon EventCode=11

Sub-techniques with coverage

Counted in the 25 above — a rule tagged a sub-technique covers this technique too.


SigmaHQ/sigma

15 rules
Detection Severity Format
Potential Manage-bde.wsf Abuse To Proxy Execution High Sigma
Suspicious CustomShellHost Execution High Sigma
Assembly Loading Via CL_LoadAssembly.ps1 Medium Sigma
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl Medium Sigma
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File Medium Sigma
Execute Code with Pester.bat Medium Sigma
Execute Code with Pester.bat as Parent Medium Sigma
Launch-VsDevShell.PS1 Proxy Execution Medium Sigma
Potential Process Execution Proxy Via CL_Invocation.ps1 Medium Sigma
Potential Script Proxy Execution Via CL_Mutexverifiers.ps1 Medium Sigma

+ 5 more from SigmaHQ/sigma → showing the 10 highest-severity

socfortress/Wazuh-Rules

5 rules · 3 families
Detection Severity Format
Sysmon - Event 1: Process creation · Pubprn.vbs remote script execution (T1216.001) High Wazuh XML
Sysmon - Event 1: Process creation · Signed Script Proxy Execution (T1216) 2 variants Low Wazuh XML
Sysmon - Event 1: Process creation · Signed Script Proxy Execution (T1216) 2 variants Low Wazuh XML
Sysmon - Event 1: Process creation · Trusted Script Proxy Execution (T1216) 2 variants Low Wazuh XML
Sysmon - Event 1: Process creation · Trusted Script Proxy Execution (T1216) 2 variants Low Wazuh XML

elastic/protections-artifacts

3 rules
Detection Severity Format
Inhibit System Recovery via Signed Binary Proxy Undefined Elastic TOML
Scriptlet Proxy Execution via PubPrn Undefined Elastic TOML
Suspicious Windows Schedule Child Process Undefined Elastic TOML

elastic/detection-rules

1 rule
Detection Severity Format
Delayed Execution via Ping Low Elastic TOML

splunk/security_content

1 rule
Detection Severity Format
Windows System Script Proxy Execution Syncappvpublishingserver Undefined SPL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.