Trusted Developer Utilities Proxy Execution T1127

Tactics: Stealth, Execution

Adversaries may take advantage of trusted developer utilities to proxy execution of malicious payloads. There are many utilities used for software development related tasks that can be used to execute code in various forms to assist in development, debugging, and reverse engineering. These utilities may often be signed with legitimate certificates that allow them to execute on a system and proxy execution of malicious code through a trusted process that effectively bypasses application control solutions.

Events covered

10 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 59 rules share fields, values, and exclusions.

Fields filtered most (35 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
OriginalFileName23eq 22, in 1msbuild.exe, microsoft.workflow.compiler.exe, \sqltoolsps.exe, cdb.exe, cscript.exe
process_name23eq 17, ne 2, regex_match 2, in 1, wildcard 1msbuild.exe, certutil.exe, (?i)msbuild\.exe, bginfo.exe, cdb.exe
Image22ends_with 18, contains 3, wildcard 2, ne 1, starts_with 1:\windows\microsoft.net\framework64\, :\windows\microsoft.net\framework\, :\windows\microsoft.net\frameworkarm64\, *\\framework*\\v*\\*, :\temp\
parent_process_name16eq 10, regex_match 4, in 2cscript.exe, explorer.exe, (?i)(cmd|powershell(_ise)?|pwsh|cscript|wscript|mshta)\.exe, (?i)^appcert.exe, cmd.exe
CommandLine15contains 9, regex_match 5, wildcard 1(?i)\stest\s, (?i)\s+\-(cf|cfr|premote|pd.*-pn|pn.*-pd)\s+, --eval , -a , -c
host.os.type15eq 15
event.type12eq 12start
EventID11eq 114688, 1, 4103, 4104, 8
ParentImage7ends_with 7\aspnet_compiler.exe, \cleanapi.exe, \kavremover.exe, \mftrace.exe, \powershell.exe
EventType5eq 5start, connection_attempted, lookup_requested
Type4eq 4
process.args3eq 1, starts_with 1, wildcard 1-n, ?:\Users\*\AppData\Local\Temp\tmp*.exec.cmd, C:\Intel\, C:\PerfLogs\, C:\ProgramData\
QueryName2is_not_null 2, regex_match 1.*\.(top|buzz|xyz|rest|ml|cf|gq|ga|onion|monster|cyou|que...
event.category2eq 2process
CurrentDirectory1starts_with 1D:\, E:\, F:\

Top indicator values (274 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
121078
process_nameeq
msbuild.exe
1239
process_nameeq
microsoft.workflow.compiler.exe
412
process_nameeq
mshta.exe
484
process_nameeq
regsvr32.exe
473
process_nameeq
rundll32.exe
4126
process_nameeq
wscript.exe
483
process_nameeq
certutil.exe
344
process_nameeq
cscript.exe
367
process_nameeq
ieexec.exe
310
process_nameeq
iexpress.exe
39
process_nameeq
installutil.exe
337
process_nameeq
powershell.exe
3184
OriginalFileNameeq
msbuild.exe
920
OriginalFileNameeq
microsoft.workflow.compiler.exe
312
EventIDeq
4688
5317
EventIDeq
1
4241
EventTypeeq
start
4391
CommandLineregex_match
(?i)\stest\s
33
CommandLineregex_match
(?i)\s+\-(cf|cfr|premote|pd.*-pn|pn.*-pd)\s+
22
parent_process_nameeq
explorer.exe
351
parent_process_nameeq
eqnedt32.exe
29
parent_process_nameeq
excel.exe
228
parent_process_nameeq
fltldr.exe
27
Imagecontains
:\windows\microsoft.net\framework64\
22
Imagecontains
:\windows\microsoft.net\framework\
22
Imagecontains
:\windows\microsoft.net\frameworkarm64\
22
Imagecontains
:\windows\microsoft.net\frameworkarm\
22
Imageends_with
\aspnet_compiler.exe
23
event.categoryeq
process
2142

Exclusions (120 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLineregex_match
(?i)\-setupcommandline
3
process_nameeq
powershell.exe
2
process_nameregex_match
(?i)\x5cprogram\sfiles(\s\(x86\))?\x5cwindows\skits\x5c10\x5c
2
CommandLinecontains
.\
1
CommandLinecontains
/
1
CommandLinecontains
.proj
1
CommandLinecontains
.sln
1
CommandLinecontains
\.nuget\packages\vswhere\
1
CommandLinecontains
adobe creative cloud experience\js
1
CommandLinecontains
common\..\..\buildtools\
1
CommandLinecontains
git log --pretty=format
1
CommandLinecontains
vswhere.exe -property catalog_productsemanticversion
1
CommandLineeq
driver\dpinst_x64 /f
1
CurrentDirectorywildcard
?:\Users\*\AppData\Local\Temp\BackupBootstrapper\Logs\
1
CurrentDirectorywildcard
?:\Users\*\AppData\Local\Temp\QBTools\
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 21 rules

Elastic 19 rules

Splunk 16 rules

Kusto 3 rules