Cross-source coverage

T1218 / ATT&CK

System Binary Proxy Execution

631 rules · 607 families across 8 sources.

10 deprecated hidden · include 1 atomic-IOC hidden · include

From MITRE ATT&CK 19.2

Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Several Microsoft signed binaries that are default on Windows installations can be used to proxy execution of other files or commands.

Similarly, on Linux systems adversaries may abuse trusted binaries such as split to proxy execution of malicious commands.

Tactics
Stealth
Platforms
Linux · macOS · Windows
Telemetry
WinEventLog:Sysmonauditd:SYSCALLmacos:unifiedlogmacos:osquery

How MITRE says to detect it DET0081

Detection of Proxy Execution via Trusted Signed Binaries Across Platforms

Windows Analytic 0226

Execution of trusted, Microsoft-signed binaries such as `rundll32.exe`, `msiexec.exe`, or `regsvr32.exe` used to execute externally hosted, unsigned, or suspicious payloads through command-line parameters or network retrieval.

  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=3, 22
  • WinEventLog:Sysmon EventCode=7

Linux Analytic 0227

Execution of trusted system binaries (e.g., `split`, `tee`, `bash`, `env`) used in uncommon sequences or chained behaviors to execute malicious payloads or perform actions inconsistent with normal system or script behavior.

  • auditd:SYSCALL execve
  • auditd:SYSCALL connect

macOS Analytic 0228

Use of system binaries such as `osascript`, `bash`, or `curl` to download or execute unsigned code or files in conjunction with application proxying.

  • macos:unifiedlog exec of osascript, bash, curl with suspicious parameters
  • macos:osquery execution of trusted tools interacting with external endpoints

Sub-techniques with coverage

Counted in the 631 above — a rule tagged a sub-technique covers this technique too.


SigmaHQ/sigma

254 rules
Detection Severity Format
APT29 2018 Phishing Campaign CommandLine Indicators Critical Sigma
APT29 2018 Phishing Campaign File Indicators Critical Sigma
Equation Group DLL_U Export Function Load Critical Sigma
EvilNum APT Golden Chickens Deployment Via OCX Files Critical Sigma
HackTool - F-Secure C3 Load by Rundll32 Critical Sigma
NotPetya Ransomware Activity Critical Sigma
Potential Emotet Rundll32 Execution Critical Sigma
ZxShell Malware Critical Sigma
Arbitrary File Download Via IMEWDBLD.EXE High Sigma
BaaUpdate.exe Suspicious DLL Load High Sigma

+ 244 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/protections-artifacts

117 rules
Detection Severity Format
BCDEdit Safe Mode Command Execution Undefined Elastic TOML
Binary Proxy Execution via AppVLP Undefined Elastic TOML
Binary Proxy Execution via Pester Undefined Elastic TOML
Binary Proxy Execution via Rundll32 Undefined Elastic TOML
Binary Proxy Execution via Runexehelper Undefined Elastic TOML
Binary Proxy Execution via TTDInject Undefined Elastic TOML
Binary Proxy Execution via Windows OpenSSH Undefined Elastic TOML
Command Shell Activity Started via RunDLL32 Undefined Elastic TOML
Connection to Dynamic DNS Provider by a Signed Binary Proxy Undefined Elastic TOML
Connection to WebService by a Signed Binary Proxy Undefined Elastic TOML

+ 107 more from elastic/protections-artifacts → showing the 10 highest-severity

splunk/security_content

93 rules
Detection Severity Format
Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI Undefined SPL
Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download Undefined SPL
Cisco NVM - Suspicious Network Connection From Process With No Args Undefined SPL
CMLUA Or CMSTPLUA UAC Bypass Undefined SPL
Control Loading from World Writable Directory Undefined SPL
Detect HTML Help Renamed Undefined SPL
Detect HTML Help Spawn Child Process Undefined SPL
Detect HTML Help URL in Command Line Undefined SPL
Detect HTML Help Using InfoTech Storage Handlers Undefined SPL
Detect mshta inline hta execution Undefined SPL

+ 83 more from splunk/security_content → showing the 10 highest-severity

elastic/detection-rules

83 rules
Detection Severity Format
Command and Scripting Interpreter via Windows Scripts High Elastic TOML
Control Panel Process with Unusual Arguments High Elastic TOML
Incoming DCOM Lateral Movement via MSHTA High Elastic TOML
Incoming DCOM Lateral Movement with MMC High Elastic TOML
Network Activity to a Suspicious Top Level Domain High Elastic TOML
Potential Credential Access via Renamed COM+ Services DLL High Elastic TOML
Potential Credential Access via Windows Utilities High Elastic TOML
Potential CVE-2025-33053 Exploitation High Elastic TOML
Potential Escalation via Vulnerable MSI Repair High Elastic TOML
Potential Execution via FileFix Phishing Attack High Elastic TOML

+ 73 more from elastic/detection-rules → showing the 10 highest-severity

socfortress/Wazuh-Rules

62 rules · 46 families
Detection Severity Format
Sysmon - Event 1: Process creation · Any hh.exe Execution (T1218.001) High Wazuh XML
Sysmon - Event 1: Process creation · CMSTP (T1218.003) 2 variants High Wazuh XML
Sysmon - Event 1: Process creation · Control Panel Items (T1218.002) 2 variants High Wazuh XML
Sysmon - Event 1: Process creation · hh.exe Decompile CHM (T1218.001) High Wazuh XML
Sysmon - Event 1: Process creation · hh.exe Executing CHM File (T1218.001) High Wazuh XML
Sysmon - Event 1: Process creation · hh.exe via PowerShell (T1218.001) High Wazuh XML
Sysmon - Event 1: Process creation · Msiexec executing DLL register/unregister (T1218.007) High Wazuh XML
Sysmon - Event 1: Process creation · Msiexec executing DLL unregister (T1218.007) High Wazuh XML
Sysmon - Event 1: Process creation · Msiexec executing local MSI (T1218.007) High Wazuh XML
Sysmon - Event 1: Process creation · Msiexec fetching remote MSI (T1218.007) High Wazuh XML

+ 52 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

Bert-JanP/Hunting-Queries-Detection-Rules

10 rules · 9 families
Detection Severity Format
Certutil Remote Download Undefined KQL
Detect when Regsvr32.exe is created as subprocess by an Office Application Undefined KQL
IPv4 command detected in lolbin execution Undefined KQL
MITRE ATT&CK Mapping Undefined KQL
MSHTA Executions Undefined KQL
New LOLBIN with external connection Undefined KQL
Outbound MSHTA Connection Undefined KQL
URL Lookup (Network & Commandline) 2 variants Undefined KQL
URL Lookup (Network & Commandline) 2 variants Undefined KQL
WMIC Remote Command Execution Undefined KQL

Wazuh Core Ruleset

7 rules
Detection Severity Format
Office application started mshta.exe and executed scripting command Critical Wazuh XML
Rundll32 executing file with suspicious extension Critical Wazuh XML
Office application invoked Verclsid.exe, possible COM payload execution High Wazuh XML
Office application started mshta.exe High Wazuh XML
Rundll32 executed from non-standard directory, may be related to link execution from mounted ISO file High Wazuh XML
Verclsid.exe may have been used to execute COM payload High Wazuh XML
Rundll32 executing suspicious .lock file, possible persistence tactic Medium Wazuh XML

Azure/Azure-Sentinel

5 rules
Detection Severity Format
Suspicious command line tokens in LolBins or LolScripts Medium KQL
regsvr32-rundll32-abnormal-image-loads Undefined KQL
regsvr32-rundll32-image-loads-abnormal-extension Undefined KQL
regsvr32-rundll32-with-anomalous-parent-process Undefined KQL
Rundll32 (LOLBins and LOLScripts, Normalized Process Events) Undefined KQL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.