System Script Proxy Execution T1216
Tactic: Stealth
Adversaries may use trusted scripts, often signed with certificates, to proxy the execution of malicious files. Several Microsoft signed scripts that have been downloaded from Microsoft or are default on Windows installations can be used to proxy execution of other files. This behavior may be abused by adversaries to execute malicious files that could bypass application control and signature validation on systems.
Events covered
3 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Sysmon | Event ID 11 | FileCreate |
| Security-Auditing | Event ID 4688 | A new process has been created. |
Authoring guide
These 22 rules share fields, values, and exclusions.
Fields filtered most (20 distinct)
These fields appear most often in rule filters.
Top indicator values (139 distinct)
These values appear most often in rule predicates.
Exclusions (107 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: Windows
Domain: Endpoint
Sigma 15 rules
- Assembly Loading Via CL_LoadAssembly.ps1
- AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl
- AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File
- Execute Code with Pester.bat
- Execute Code with Pester.bat as Parent
- Launch-VsDevShell.PS1 Proxy Execution
- Potential Manage-bde.wsf Abuse To Proxy Execution
- Potential Process Execution Proxy Via CL_Invocation.ps1
- Potential Script Proxy Execution Via CL_Mutexverifiers.ps1
- Pubprn.vbs Proxy Execution
- Remote Code Execute via Winrm.vbs
- Suspicious CustomShellHost Execution
- SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code
- Uncommon Sigverif.EXE Child Process
- UtilityFunctions.ps1 Proxy Dll
Elastic 4 rules
- Delayed Execution via Ping
- Inhibit System Recovery via Signed Binary Proxy
- Scriptlet Proxy Execution via PubPrn
- Suspicious Windows Schedule Child Process