System Script Proxy Execution T1216

Tactic: Stealth

Adversaries may use trusted scripts, often signed with certificates, to proxy the execution of malicious files. Several Microsoft signed scripts that have been downloaded from Microsoft or are default on Windows installations can be used to proxy execution of other files. This behavior may be abused by adversaries to execute malicious files that could bypass application control and signature validation on systems.

Events covered

3 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 22 rules share fields, values, and exclusions.

Fields filtered most (20 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine17contains 14, wildcard 3, regex_match 2, length_compare 1(?i)\s+-[ilsx]*c[ilsx]*, ;, -e , -enc, -nologo -windowstyle minimized -file
Image9ends_with 4, eq 2, starts_with 2, wildcard 1\cmd.exe, \powershell.exe, ?:\programdata\, ?:\users\, ?:\users\*\appdata\*.exe
OriginalFileName5eq 4, in 1cscript.exe, wscript.exe, bcdedit.exe, cmd.exe, installutil.exe
ParentImage5ends_with 5\powershell.exe, \pwsh.exe, \cscript.exe, \customshellhost.exe, \sigverif.exe
EventType4eq 4start
process_name4regex_match 2, eq 1, in 1(?i)bash\.exe, cscript.exe, certutil.exe, ieexec.exe, wscript.exe
EventID2eq 21, 4688
ParentCommandLine2contains 2\windowspowershell\modules\pester\, manage-bde.wsf, { get-help ", { invoke-pester -enableexit ;
event_count2lt 25
parent_process_name2eq 2cmd.exe, svchost.exe
process.args2eq 1, wildcard 1*,#*, -n, ?:\ProgramData\*, ?:\Users\*
Hashes1is_not_null 1
TargetFilename1ends_with 1, starts_with 1c:\windows\system32\, c:\windows\syswow64\, wsmpty.xsl
Type1eq 1
host.os.type1eq 1

Top indicator values (139 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypeeq
start
4391
CommandLinecontains
;
22
CommandLinecontains
winrm
22
CommandLinecontains
-e
117
CommandLinecontains
-enc
12
CommandLinecontains
-nologo -windowstyle minimized -file
1
CommandLinecontains
-r:http
1
CommandLinecontains
?
1
CommandLinecontains
\appdata\local\temp\
128
CommandLinecontains
\pubprn.vbs
1
CommandLinecontains
\syncappvpublishingserver.vbs
1
CommandLinecontains
\windows\temp\
113
CommandLinecontains
bootstatuspolicy
110
CommandLinecontains
catalog
112
CommandLinecontains
delete
131
CommandLinecontains
format:"pretty"
1
CommandLinecontains
format:"text"
1
CommandLinecontains
format:pretty
1
CommandLinecontains
format:text
1
CommandLinecontains
get-help
1
CommandLinecontains
help
1
CommandLinecontains
invoke create wmicimv2/win32_
1
CommandLinecontains
launch-vsdevshell.ps1
1
CommandLineregex_match
(?i)\s+-[ilsx]*c[ilsx]*
22
Imageends_with
\cmd.exe
2130
Imageends_with
\powershell.exe
2179
ParentImageends_with
\powershell.exe
224
ParentImageends_with
\pwsh.exe
221
event_countlt
5
23
process_nameregex_match
(?i)bash\.exe
22

Exclusions (107 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process_nameeq
powershell.exe
2
process_nameeq
regsvr32.exe
2
CommandLinecontains
\programdata\servicenow\agent-client-collector\config\acc.yml
1
CommandLineeq
driver\dpinst_x64 /f
1
CurrentDirectorywildcard
?:\Users\*\AppData\Local\Temp\BackupBootstrapper\Logs\
1
CurrentDirectorywildcard
?:\Users\*\AppData\Local\Temp\QBTools\
1
CurrentDirectorywildcard
?:\Windows\TempInst\*
1
Hashesin
02a31b0fcb2603643518fb1a164a7a2abe8f3f494daf88ebc3d93c9b98a50e46
1
Hashesin
053c6a0f59672b06e9ebccff18f2517780ff4c77ada25ac3eee1f2c4a24e8aea
1
Hashesin
15eaff644e9a34e49997d57c4c21ce18dab4714321a62eae4252bd8eca1f3f9d
1
Hashesin
18fb4e476f670b532d5227fc8ff9d7d55c151102875d64e80f2dc0cbd569861c
1
Hashesin
1a6b98956fb92a8a57b56feeef6fedc26b95c809526374f6e7c22acd8e3925c3
1
Hashesin
22e7528e56dffaa26cfe722994655686c90824b13eb51184abfe44d4e95d473f
1
Hashesin
3a87ed304e359392da91bc39cb17af379dcd906c045ffcc4d715086d766acfbc
1
Hashesin
41512ecc47bb39b9f39c808f89ab23df4a4e88e414215553b825e140a4509946
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Windows

Domain: Endpoint

Sigma 15 rules

Elastic 4 rules

Splunk 3 rules