Cross-source coverage
T1218 / ATT&CK
System Binary Proxy Execution
631 rules · 607 families across 8 sources.
10 deprecated hidden · include 1 atomic-IOC hidden · include
From MITRE ATT&CK 19.2
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Several Microsoft signed binaries that are default on Windows installations can be used to proxy execution of other files or commands.
Similarly, on Linux systems adversaries may abuse trusted binaries such as split to proxy execution of malicious commands.
- Tactics
- Stealth
- Platforms
- Linux · macOS · Windows
- Telemetry
-
WinEventLog:Sysmonauditd:SYSCALLmacos:unifiedlogmacos:osquery
How MITRE says to detect it DET0081
Detection of Proxy Execution via Trusted Signed Binaries Across Platforms
Windows Analytic 0226
Execution of trusted, Microsoft-signed binaries such as `rundll32.exe`, `msiexec.exe`, or `regsvr32.exe` used to execute externally hosted, unsigned, or suspicious payloads through command-line parameters or network retrieval.
WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=3, 22WinEventLog:SysmonEventCode=7
Linux Analytic 0227
Execution of trusted system binaries (e.g., `split`, `tee`, `bash`, `env`) used in uncommon sequences or chained behaviors to execute malicious payloads or perform actions inconsistent with normal system or script behavior.
auditd:SYSCALLexecveauditd:SYSCALLconnect
macOS Analytic 0228
Use of system binaries such as `osascript`, `bash`, or `curl` to download or execute unsigned code or files in conjunction with application proxying.
macos:unifiedlogexec of osascript, bash, curl with suspicious parametersmacos:osqueryexecution of trusted tools interacting with external endpoints
Sub-techniques with coverage
Counted in the 631 above — a rule tagged a sub-technique covers this technique too.
SigmaHQ/sigma
254 rules| Detection | Severity | Format |
|---|---|---|
| APT29 2018 Phishing Campaign CommandLine Indicators | Critical | Sigma |
| APT29 2018 Phishing Campaign File Indicators | Critical | Sigma |
| Equation Group DLL_U Export Function Load | Critical | Sigma |
| EvilNum APT Golden Chickens Deployment Via OCX Files | Critical | Sigma |
| HackTool - F-Secure C3 Load by Rundll32 | Critical | Sigma |
| NotPetya Ransomware Activity | Critical | Sigma |
| Potential Emotet Rundll32 Execution | Critical | Sigma |
| ZxShell Malware | Critical | Sigma |
| Arbitrary File Download Via IMEWDBLD.EXE | High | Sigma |
| BaaUpdate.exe Suspicious DLL Load | High | Sigma |
+ 244 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/protections-artifacts
117 rules| Detection | Severity | Format |
|---|---|---|
| BCDEdit Safe Mode Command Execution | Undefined | Elastic TOML |
| Binary Proxy Execution via AppVLP | Undefined | Elastic TOML |
| Binary Proxy Execution via Pester | Undefined | Elastic TOML |
| Binary Proxy Execution via Rundll32 | Undefined | Elastic TOML |
| Binary Proxy Execution via Runexehelper | Undefined | Elastic TOML |
| Binary Proxy Execution via TTDInject | Undefined | Elastic TOML |
| Binary Proxy Execution via Windows OpenSSH | Undefined | Elastic TOML |
| Command Shell Activity Started via RunDLL32 | Undefined | Elastic TOML |
| Connection to Dynamic DNS Provider by a Signed Binary Proxy | Undefined | Elastic TOML |
| Connection to WebService by a Signed Binary Proxy | Undefined | Elastic TOML |
+ 107 more from elastic/protections-artifacts → showing the 10 highest-severity
splunk/security_content
93 rules| Detection | Severity | Format |
|---|---|---|
| Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI | Undefined | SPL |
| Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download | Undefined | SPL |
| Cisco NVM - Suspicious Network Connection From Process With No Args | Undefined | SPL |
| CMLUA Or CMSTPLUA UAC Bypass | Undefined | SPL |
| Control Loading from World Writable Directory | Undefined | SPL |
| Detect HTML Help Renamed | Undefined | SPL |
| Detect HTML Help Spawn Child Process | Undefined | SPL |
| Detect HTML Help URL in Command Line | Undefined | SPL |
| Detect HTML Help Using InfoTech Storage Handlers | Undefined | SPL |
| Detect mshta inline hta execution | Undefined | SPL |
+ 83 more from splunk/security_content → showing the 10 highest-severity
elastic/detection-rules
83 rules| Detection | Severity | Format |
|---|---|---|
| Command and Scripting Interpreter via Windows Scripts | High | Elastic TOML |
| Control Panel Process with Unusual Arguments | High | Elastic TOML |
| Incoming DCOM Lateral Movement via MSHTA | High | Elastic TOML |
| Incoming DCOM Lateral Movement with MMC | High | Elastic TOML |
| Network Activity to a Suspicious Top Level Domain | High | Elastic TOML |
| Potential Credential Access via Renamed COM+ Services DLL | High | Elastic TOML |
| Potential Credential Access via Windows Utilities | High | Elastic TOML |
| Potential CVE-2025-33053 Exploitation | High | Elastic TOML |
| Potential Escalation via Vulnerable MSI Repair | High | Elastic TOML |
| Potential Execution via FileFix Phishing Attack | High | Elastic TOML |
+ 73 more from elastic/detection-rules → showing the 10 highest-severity
socfortress/Wazuh-Rules
62 rules · 46 families| Detection | Severity | Format |
|---|---|---|
| Sysmon - Event 1: Process creation · Any hh.exe Execution (T1218.001) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · CMSTP (T1218.003) 2 variants | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Control Panel Items (T1218.002) 2 variants | High | Wazuh XML |
| Sysmon - Event 1: Process creation · hh.exe Decompile CHM (T1218.001) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · hh.exe Executing CHM File (T1218.001) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · hh.exe via PowerShell (T1218.001) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Msiexec executing DLL register/unregister (T1218.007) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Msiexec executing DLL unregister (T1218.007) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Msiexec executing local MSI (T1218.007) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Msiexec fetching remote MSI (T1218.007) | High | Wazuh XML |
+ 52 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
Bert-JanP/Hunting-Queries-Detection-Rules
10 rules · 9 families| Detection | Severity | Format |
|---|---|---|
| Certutil Remote Download | Undefined | KQL |
| Detect when Regsvr32.exe is created as subprocess by an Office Application | Undefined | KQL |
| IPv4 command detected in lolbin execution | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
| MSHTA Executions | Undefined | KQL |
| New LOLBIN with external connection | Undefined | KQL |
| Outbound MSHTA Connection | Undefined | KQL |
| URL Lookup (Network & Commandline) 2 variants | Undefined | KQL |
| URL Lookup (Network & Commandline) 2 variants | Undefined | KQL |
| WMIC Remote Command Execution | Undefined | KQL |
Wazuh Core Ruleset
7 rules| Detection | Severity | Format |
|---|---|---|
| Office application started mshta.exe and executed scripting command | Critical | Wazuh XML |
| Rundll32 executing file with suspicious extension | Critical | Wazuh XML |
| Office application invoked Verclsid.exe, possible COM payload execution | High | Wazuh XML |
| Office application started mshta.exe | High | Wazuh XML |
| Rundll32 executed from non-standard directory, may be related to link execution from mounted ISO file | High | Wazuh XML |
| Verclsid.exe may have been used to execute COM payload | High | Wazuh XML |
| Rundll32 executing suspicious .lock file, possible persistence tactic | Medium | Wazuh XML |
Azure/Azure-Sentinel
5 rules| Detection | Severity | Format |
|---|---|---|
| Suspicious command line tokens in LolBins or LolScripts | Medium | KQL |
| regsvr32-rundll32-abnormal-image-loads | Undefined | KQL |
| regsvr32-rundll32-image-loads-abnormal-extension | Undefined | KQL |
| regsvr32-rundll32-with-anomalous-parent-process | Undefined | KQL |
| Rundll32 (LOLBins and LOLScripts, Normalized Process Events) | Undefined | KQL |