System Binary Proxy Execution T1218
Tactic: Stealth
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Several Microsoft signed binaries that are default on Windows installations can be used to proxy execution of other files or commands.
Events covered
42 catalog events are tagged with this technique by at least one rule.
Authoring guide
Patterns shared across the 552 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (109 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (3006 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (923 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 254 rules
- Abusing Print Executable
- AddinUtil.EXE Execution From Uncommon Directory
- AgentExecutor PowerShell Execution
- APT29 2018 Phishing Campaign CommandLine Indicators
- APT29 2018 Phishing Campaign File Indicators
- Arbitrary Command Execution Using WSL
- Arbitrary DLL or Csproj Code Execution Via Dotnet.EXE
- Arbitrary File Download Via IMEWDBLD.EXE
- Arbitrary File Download Via MSEDGE_PROXY.EXE
- Arbitrary File Download Via MSOHTMED.EXE
- Arbitrary File Download Via MSPUB.EXE
- Arbitrary File Download Via PresentationHost.EXE
- Arbitrary File Download Via Squirrel.EXE
- Arbitrary MSI Download Via Devinit.EXE
- Atbroker Registry Change
- BaaUpdate.exe Suspicious DLL Load
- Bad Opsec Defaults Sacrificial Processes With Improper Arguments
- Binary Proxy Execution Via Dotnet-Trace.EXE
- BitLockerTogo.EXE Execution
- Bypass UAC via CMSTP
- CMSTP Execution Process Access
- CMSTP Execution Process Creation
- CMSTP Execution Registry Event
- CMSTP UAC Bypass via COM Object Access
- CobaltStrike Load by Rundll32
- Code Execution via Pcwutl.dll
- COM Object Execution via Xwizard.EXE
- Control Panel Items
- Created Files by Microsoft Sync Center
- Csc.EXE Execution Form Potentially Suspicious Parent
- Curl Download And Execute Combination
- DeviceCredentialDeployment Execution
- Devtoolslauncher.exe Executes Specified Binary
- Diskshadow Child Process Spawned
- Diskshadow Script Mode - Execution From Potential Suspicious Location
- Diskshadow Script Mode - Uncommon Script Extension Execution
- Diskshadow Script Mode Execution
- DLL Call by Ordinal Via Rundll32.EXE
- DLL Execution via Rasautou.exe
- DLL Loaded From Suspicious Location Via Cmspt.EXE
- DLL Loaded via CertOC.EXE
- Dllhost.EXE Initiated Network Connection To Non-Local IP Address
- DllUnregisterServer Function Call Via Msiexec.EXE
- DNS Query Request By Regsvr32.EXE
- Driver/DLL Installation Via Odbcconf.EXE
- Equation Group DLL_U Export Function Load
- EvilNum APT Golden Chickens Deployment Via OCX Files
- Execute Files with Msdeploy.exe
- Execute Pcwrun.EXE To Leverage Follina
- Execution DLL of Choice Using WAB.EXE
- Execution via stordiag.exe
- Execution via WorkFolders.exe
- File Download Using ProtocolHandler.exe
- File Download Via InstallUtil.EXE
- File Download Via Windows Defender MpCmpRun.EXE
- Fireball Archer Install
- Gpscript Execution
- HackTool - CACTUSTORCH Remote Thread Creation
- HackTool - F-Secure C3 Load by Rundll32
- HackTool - RedMimicry Winnti Playbook Execution
- HH.EXE Execution
- HH.EXE Initiated HTTP Network Connection
- Hidden Flag Set On File/Directory Via Chflags - MacOS
- HTML Help HH.EXE Suspicious Child Process
- IcedID Malware Suspicious Single Digit DLL Execution Via Rundll32
- Ie4uinit Lolbin Use From Invalid Path
- Import LDAP Data Interchange Format File Via Ldifde.EXE
- Indirect Command Execution By Program Compatibility Wizard
- InfDefaultInstall.exe .inf Execution
- Insensitive Subfolder Search Via Findstr.EXE
- Kapeka Backdoor Execution Via RunDLL32.EXE
- Kapeka Backdoor Loaded Via Rundll32.EXE
- Legitimate Application Dropped Archive
- Legitimate Application Dropped Executable
- Legitimate Application Dropped Script
- Legitimate Application Writing Files In Uncommon Location
- Lolbin Runexehelper Use As Proxy
- Lolbin Unregmp2.exe Use As Proxy
- Malicious PE Execution by Microsoft Visual Studio Debugger
- Malicious Windows Script Components File Execution by TAEF Detection
- Mavinject Inject DLL Into Running Process
- Microsoft Sync Center Suspicious Network Connections
- Microsoft Workflow Compiler Execution
- MMC Executing Files with Reversed Extensions Using RTLO Abuse
- MMC Loading Script Engines DLLs
- MpiExec Lolbin
- MSDT Execution Via Answer File
- MSHTA Execution with Suspicious File Extensions
- MSI Installation From Web
- Msiexec Quiet Installation
- MsiExec Web Install
- Msiexec.EXE Initiated Network Connection Over HTTP
- Network Connection Initiated By AddinUtil.EXE
- Network Connection Initiated By Regsvr32.EXE
- New Capture Session Launched Via DXCap.EXE
- New DLL Registered Via Odbcconf.EXE
- New Self Extracting Package Created Via IExpress.EXE
- NotPetya Ransomware Activity
- Obfuscated PowerShell MSI Install via WindowsInstaller COM
- Odbcconf.EXE Suspicious DLL Location
- OneNote.EXE Execution of Malicious Embedded Scripts
- OpenWith.exe Executes Specified Binary
- Outbound Network Connection Initiated By Cmstp.EXE
- Outbound Network Connection To Public IP Via Winlogon
- Potential Application Whitelisting Bypass via Dnx.EXE
- Potential APT-C-12 BlueMushroom DLL Load Activity Via Regsvr32
- Potential Arbitrary File Download Via Cmdl32.EXE
- Potential Baby Shark Malware Activity
- Potential Binary Impersonating Sysinternals Tools
- Potential Binary Proxy Execution Via Cdb.EXE
- Potential Binary Proxy Execution Via VSDiagnostics.EXE
- Potential Bumblebee Remote Thread Creation
- Potential Compromised 3CXDesktopApp Execution
- Potential Compromised 3CXDesktopApp Update Activity
- Potential Devil Bait Malware Reconnaissance
- Potential DLL Sideloading Activity Via ExtExport.EXE
- Potential DLL Sideloading Using Coregen.exe
- Potential Emotet Rundll32 Execution
- Potential EmpireMonkey Activity
- Potential Exploitation of RCE Vulnerability CVE-2025-33053
- Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Image Load
- Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Process Access
- Potential File Download Via MS-AppInstaller Protocol Handler
- Potential LethalHTA Technique Execution
- Potential Mpclient.DLL Sideloading Via OfflineScannerShell.EXE Execution
- Potential NTLM Coercion Via Certutil.EXE
- Potential Password Spraying Attempt Using Dsacls.EXE
- Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE
- Potential PowerShell Execution Via DLL
- Potential Provisioning Registry Key Abuse For Binary Proxy Execution
- Potential Provisioning Registry Key Abuse For Binary Proxy Execution - REG
- Potential Provlaunch.EXE Binary Proxy Execution Abuse
- Potential Proxy Execution Via Explorer.EXE From Shell Process
- Potential Raspberry Robin CPL Execution Activity
- Potential Register_App.Vbs LOLScript Abuse
- Potential Regsvr32 Commandline Flag Anomaly
- Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell Module
- Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell ScriptBlock
- Potential Suspicious Child Process Of 3CXDesktopApp
- Potential Suspicious Mofcomp Execution
- Potentially Over Permissive Permissions Granted Using Dsacls.EXE
- Potentially Suspicious Cabinet File Expansion
- Potentially Suspicious Child Process Of DiskShadow.EXE
- Potentially Suspicious Child Process Of Regsvr32
- Potentially Suspicious Child Process Of VsCode
- Potentially Suspicious Child Processes Spawned by ConHost
- Potentially Suspicious CMD Shell Output Redirect
- Potentially Suspicious DLL Registered Via Odbcconf.EXE
- Potentially Suspicious Execution Of Regasm/Regsvcs From Uncommon Location
- Potentially Suspicious Execution Of Regasm/Regsvcs With Uncommon Extension
- Potentially Suspicious Regsvr32 HTTP IP Pattern
- Potentially Suspicious Regsvr32 HTTP/FTP Pattern
- Potentially Suspicious Rundll32 Activity
- Potentially Suspicious Rundll32.EXE Execution of UDL File
- Potentially Suspicious Self Extraction Directive File Created
- Potentially Suspicious Wuauclt Network Connection
- PowerShell MSI Install via WindowsInstaller COM From Remote Location
- PowerShell WMI Win32_Product Install MSI
- Process Access via TrolleyExpress Exclusion
- Process Memory Dump Via Dotnet-Dump
- Process Proxy Execution Via Squirrel.EXE
- Program Executed Using Proxy/Local Command Via SSH.EXE
- Proxy Execution Via Wuauclt.EXE
- RegAsm.EXE Execution Without CommandLine Flags or Files
- RegAsm.EXE Initiating Network Connection To Public IP
- REGISTER_APP.VBS Proxy Execution
- Regsvr32 DLL Execution With Suspicious File Extension
- Regsvr32 Execution From Highly Suspicious Location
- Regsvr32 Execution From Potential Suspicious Location
- Regsvr32.EXE Calling of DllRegisterServer Export Function Implicitly
- Remote CHM File Download/Execution Via HH.EXE
- Remote File Download Via Findstr.EXE
- Remote Thread Creation Via PowerShell In Uncommon Target
- RemoteFXvGPUDisablement Abuse Via AtomicTestHarnesses
- Remotely Hosted HTA File Executed Via Mshta.EXE
- Renamed Mavinject.EXE Execution
- Renamed MegaSync Execution
- Renamed ZOHO Dctask64 Execution
- Response File Execution Via Odbcconf.EXE
- Rhadamanthys Stealer Module Launch Via Rundll32.EXE
- Rundll32 Execution With Uncommon DLL Extension
- Rundll32 InstallScreenSaver Execution
- Rundll32 Internet Connection
- RunDLL32 Spawning Explorer
- Rundll32 UNC Path Execution
- Rundll32.EXE Calling DllRegisterServer Export Function Explicitly
- Scheduled Task Creation with Curl and PowerShell Execution Combo
- SCR File Write Event
- ScreenSaver Registry Key Set
- Scripting/CommandLine Process Spawned Regsvr32
- Sdiagnhost Calling Suspicious Child Process
- Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location
- Self Extraction Directive File Created In Potentially Suspicious Location
- Sensitive File Dump Via Print.EXE
- Shell32 DLL Execution in Suspicious Directory
- Sofacy Trojan Loader Activity
- Suspicious AddinUtil.EXE CommandLine Execution
- Suspicious AgentExecutor PowerShell Execution
- Suspicious BitLocker Access Agent Update Utility Execution
- Suspicious Child Process Of BgInfo.EXE
- Suspicious Control Panel DLL Load
- Suspicious Csi.exe Usage
- Suspicious DLL Loaded via CertOC.EXE
- Suspicious DotNET CLR Usage Log Artifact
- Suspicious Driver/DLL Installation Via Odbcconf.EXE
- Suspicious HH.EXE Execution
- Suspicious JavaScript Execution Via Mshta.EXE
- Suspicious Microsoft Office Child Process
- Suspicious MSDT Parent Process
- Suspicious MSHTA Child Process
- Suspicious MsiExec Embedding Parent
- Suspicious Msiexec Execute Arbitrary DLL
- Suspicious Msiexec Quiet Install From Remote Location
- Suspicious Provlaunch.EXE Child Process
- Suspicious Regsvr32 Execution From Remote Share
- Suspicious Response File Execution Via Odbcconf.EXE
- Suspicious Rundll32 Activity Invoking Sys File
- Suspicious Rundll32 Execution With Image Extension
- Suspicious Rundll32 Setupapi.dll Activity
- Suspicious ShellExec_RunDLL Call Via Ordinal
- Suspicious Speech Runtime Binary Child Process
- Suspicious Vsls-Agent Command With AgentExtensionPath Load
- Suspicious WMIC Execution Via Office Process
- Suspicious WmiPrvSE Child Process
- Suspicious ZipExec Execution
- SyncAppvPublishingServer Bypass Powershell Restriction - PS Module
- SyncAppvPublishingServer Execute Arbitrary PowerShell Code
- SyncAppvPublishingServer Execution to Bypass Powershell Restriction
- SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code
- Time Travel Debugging Utility Usage
- Time Travel Debugging Utility Usage - Image
- Uncommon Assistive Technology Applications Execution Via AtBroker.EXE
- Uncommon AddinUtil.EXE CommandLine Execution
- Uncommon Child Process Of AddinUtil.EXE
- Uncommon Child Process Of Appvlp.EXE
- Uncommon Child Process Of BgInfo.EXE
- Uncommon Child Process Of Defaultpack.EXE
- Uncommon Child Process Of Setres.EXE
- Uncommon Child Process Spawned By Odbcconf.EXE
- Uncommon Link.EXE Parent Process
- Unsigned DLL Loaded by Windows Utility
- Use of Scriptrunner.exe
- Use Of The SFTP.EXE Binary As A LOLBIN
- Use of VisualUiaVerifyNative.exe
- Verclsid.exe Runs COM Object
- Visual Studio NodejsTools PressAnyKey Arbitrary Binary Execution
- Visual Studio NodejsTools PressAnyKey Renamed Execution
- Windows MSIX Package Support Framework AI_STUBS Execution
- Windows Shell/Scripting Processes Spawning Suspicious Programs
- Winrs Local Command Execution
- Wlrmdr.EXE Uncommon Argument Or Child Process
- WSL Child Process Anomaly
- XBAP Execution From Uncommon Locations Via PresentationHost.EXE
- ZxShell Malware
Elastic 88 rules
- Command and Scripting Interpreter via Windows Scripts
- Command Shell Activity Started via RunDLL32
- Control Panel Process with Unusual Arguments
- Creation of SettingContent-ms Files
- Curl or Wget Egress Network Connection via LoLBin
- Delayed Execution via Ping
- Dynamic Linker (ld.so) Creation
- Execution from Unusual Directory - Command Line
- Execution of a Downloaded Windows Script
- Execution of COM object via Xwizard
- Execution of Persistent Suspicious Program
- Execution via GitHub Actions Runner
- Execution via Microsoft DotNet ClickOnce Host
- Execution via OpenClaw Agent
- Execution via Windows Command Debugging Utility
- File or Directory Deletion Command
- File with Suspicious Extension Downloaded
- Host Detected with Suspicious Windows Process(es)
- ImageLoad via Windows Update Auto Update Client
- Incoming DCOM Lateral Movement via MSHTA
- Incoming DCOM Lateral Movement with MMC
- InstallUtil Activity
- InstallUtil Process Making Network Connections
- Microsoft Build Engine Started by a Script Process
- Microsoft Management Console File from Unusual Path
- Mshta Making Network Connections
- MsiExec Service Child Process With Network Connection
- Network Activity to a Suspicious Top Level Domain
- Network Connection via Certutil
- Network Connection via Compiled HTML File
- Network Connection via Registration Utility
- Network Connection via Signed Binary
- Parent Process Detected with Suspicious Windows Process(es)
- Persistence via a Windows Installer
- Potential Command and Control via Internet Explorer
- Potential Credential Access via Renamed COM+ Services DLL
- Potential Credential Access via Windows Utilities
- Potential CVE-2025-33053 Exploitation
- Potential Defense Evasion via CMSTP.exe
- Potential Escalation via Vulnerable MSI Repair
- Potential Execution via FileFix Phishing Attack
- Potential Fake CAPTCHA Phishing Attack
- Potential File Transfer via Certreq
- Potential Local NTLM Relay via HTTP
- Potential Privilege Escalation via SUID/SGID Proxy Execution
- Potential Protocol Tunneling via Yuze
- Potential Remote File Execution via MSIEXEC
- Potential Remote Install via MsiExec
- Potentially Suspicious Process Started via tmux or screen
- Process Activity via Compiled HTML File
- Proxy Shell Execution via Busybox
- Rare Connection to WebDAV Target
- Script Execution via Microsoft HTML Application
- Service Control Spawned via Script Interpreter
- Signed Proxy Execution via MS Work Folders
- Suspicious .NET Code Compilation
- Suspicious Execution from a Mounted Device
- Suspicious Execution from VS Code Extension
- Suspicious Execution via MSIEXEC
- Suspicious Explorer Child Process
- Suspicious JetBrains TeamCity Child Process
- Suspicious Managed Code Hosting Process
- Suspicious Microsoft Diagnostics Wizard Execution
- Suspicious Microsoft HTML Application Child Process
- Suspicious MS Office Child Process
- Suspicious MS Outlook Child Process
- Suspicious PDF Reader Child Process
- Suspicious ScreenConnect Client Child Process
- Suspicious Script Object Execution
- Suspicious Shell Execution via Velociraptor
- Suspicious SolarWinds Web Help Desk Java Module Load or Child Process
- Suspicious Troubleshooting Pack Cabinet Execution
- Suspicious Windows Command Shell Arguments
- Suspicious WMIC XSL Script Execution
- UAC Bypass Attempt via Elevated COM Internet Explorer Add-On Installer
- UAC Bypass via Windows Firewall Snap-In Hijack
- Unusual Child Processes of RunDLL32
- Unusual Execution via Microsoft Common Console File
- Unusual Network Activity from a Windows System Binary
- Unusual Network Connection via DllHost
- Unusual Network Connection via RunDLL32
- Unusual Process Network Connection
- Unusual Process Spawned by a Host
- Unusual Process Spawned by a Parent Process
- Unusual Process Spawned by a User
- User Detected with Suspicious Windows Process(es)
- Windows Installer with Suspicious Properties
- Windows Server Update Service Spawning Suspicious Processes
Splunk 203 rules
- .msc Executed from Unusual Location (Sysmon)
- .msc Executed from Unusual Location (Windows Event Log)
- 3CXDesktopApp.exe Execution (EDR)
- 3CXDesktopApp.exe Execution (Sysmon)
- 3CXDesktopApp.exe Execution (Windows Event Log)
- ATBroker.exe Execution (PowerShell)
- ATBroker.exe Execution (Sysmon)
- ATBroker.exe Execution (Windows Event Log)
- Bash -c Execution - Windows (Sysmon)
- Bash -c Execution - Windows (Windows Event Log)
- Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI
- Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download
- Cisco NVM - Suspicious Network Connection From Process With No Args
- CMLUA Or CMSTPLUA UAC Bypass
- Cmstp Execution (Sysmon)
- Cmstp Execution (Windows Event Log)
- Control Loading from World Writable Directory
- Control Panel Abuse (Sysmon)
- Control Panel Abuse (Windows Event Log)
- Control_RunDLL Call from Command Line (Sysmon)
- Control_RunDLL Call from Command Line (Windows Event Log)
- Detect HTML Help Renamed
- Detect HTML Help Spawn Child Process
- Detect HTML Help URL in Command Line
- Detect HTML Help Using InfoTech Storage Handlers
- Detect mshta inline hta execution
- Detect mshta renamed
- Detect MSHTA Url in Command Line
- Detect Regasm Spawning a Process
- Detect Regasm with Network Connection
- Detect Regasm with no Command Line Arguments
- Detect Regsvcs Spawning a Process
- Detect Regsvcs with Network Connection
- Detect Regsvcs with No Command Line Arguments
- Detect Regsvr32 Application Control Bypass
- Detect Rundll32 Inline HTA Execution
- DLL Called with RS32 (PowerShell)
- DLL Called with RS32 (Sysmon)
- DLL Called with RS32 (Windows Event Log)
- DLL Called with Uncommon Function (PowerShell)
- DLL Called with Uncommon Function (Sysmon)
- DLL Called with Uncommon Function (Windows Event Log)
- DLL Execution from Uncommon Process (PowerShell)
- DLL Execution from Uncommon Process (Sysmon)
- DLL Execution from Uncommon Process (Windows Event Log)
- DLLRegisterServer Called from Command Line (PowerShell)
- DLLRegisterServer Called from Command Line (Sysmon)
- DLLRegisterServer Called from Command Line (Windows Event Log)
- DNX.exe Proxy Execution (Windows Event Log)
- Dotnet.exe Execution (Windows Event Log)
- Driver as Command Parameter (Windows Event Log)
- Dxcap Proxy Execution (Windows Event Log)
- Executable Process from Suspicious Folder (PowerShell)
- Executable Process from Suspicious Folder (Sysmon)
- Executable Process from Suspicious Folder (Windows Event Log)
- Group Policy Editor Execution (PowerShell)
- Group Policy Editor Execution (Sysmon)
- Group Policy Editor Execution (Windows Event Log)
- hh.exe Execution (PowerShell)
- hh.exe Execution (Sysmon)
- hh.exe Execution (Windows Event Log)
- hh.exe Remote File Execution (PowerShell)
- hh.exe Remote File Execution (Sysmon)
- hh.exe Remote File Execution (Windows Event Log)
- IIS Worker (W3WP) Spawn Command Line (Windows Event Log)
- LOLBAS With Network Traffic
- Malicious InProcServer32 Modification
- Mavinject Execution (EDR)
- Mavinject Execution (Sysmon)
- Mavinject Execution (Windows Event Log)
- Mmc LOLBAS Execution Process Spawn
- Mshta spawning Rundll32 OR Regsvr32 Process
- MSHTA.exe execution (PowerShell)
- MSHTA.exe execution (Sysmon)
- MSHTA.exe execution (Windows Event Log)
- mshta.exe File Download (PowerShell)
- mshta.exe File Download (Sysmon)
- mshta.exe File Download (Windows Event Log)
- MSI Installation via Appcert (PowerShell)
- MSI Installation via Appcert (Sysmon)
- MSI Installation via Appcert (Windows Event Log)
- Msiexec Abuse (Sysmon)
- Msiexec Abuse (Windows Event Log)
- MSIExec Install MSI File (Sysmon)
- MSIExec Install MSI File (Windows Event Log)
- MSIExec.exe Execution (Sysmon)
- MSIExec.exe Execution (Windows Event Log)
- Nslookup Execution (Windows Event Log)
- Possible Lateral Movement PowerShell Spawn
- Potential Sysinternals Tool Execution (PowerShell)
- Potential Sysinternals Tool Execution (Sysmon)
- Potential Sysinternals Tool Execution (Windows Event Log)
- Process Creation Using Sysnative Folder (Sysmon)
- Process Creation Using Sysnative Folder (Windows Event Log)
- regsvr32 Execution (PowerShell)
- regsvr32 Execution (Sysmon)
- regsvr32 Execution (Windows Event Log)
- regsvr32 Referencing Unusual Paths (Sysmon)
- regsvr32 Referencing Unusual Paths (Windows Event Log)
- Regsvr32 Silent and Install Param Dll Loading
- Regsvr32 with Known Silent Switch Cmdline
- Remote .msi Installation (PowerShell)
- Remote .msi Installation (PowerShell)
- Remote .msi Installation (Sysmon)
- Remote .msi Installation (Sysmon)
- Remote .msi Installation (Windows Event Log)
- Remote .msi Installation (Windows Event Log)
- RunDLL Loading DLL By Ordinal
- Rundll32 Command Line (PowerShell)
- Rundll32 Command Line (Sysmon)
- Rundll32 Command Line (Windows Event Log)
- Rundll32 Control RunDLL Hunt
- Rundll32 Control RunDLL World Writable Directory
- Rundll32 DNSQuery
- Rundll32 LockWorkStation
- Rundll32 Process Creating Exe Dll Files
- Rundll32 Suspicious Command Line (PowerShell)
- Rundll32 Suspicious Command Line (Sysmon)
- Rundll32 Suspicious Command Line (Windows Event Log)
- rundll32 Suspicious Parent Process (Sysmon)
- rundll32 Suspicious Parent Process (Windows Event Log)
- Rundll32 with no Command Line Arguments with Network
- rundll32 with No DLL in Command Line (Sysmon)
- rundll32 with No DLL in Command Line (Windows Event Log)
- Rundll32.exe as Parent Process (Sysmon)
- Rundll32.exe as Parent Process (Windows Event Log)
- rundll32.exe Executing DLL from Non-standard Directory (PowerShell)
- rundll32.exe Executing DLL from Non-standard Directory (Sysmon)
- rundll32.exe Executing DLL from Non-standard Directory (Windows Event Log)
- Shell Spawned by Web Server - Windows (Windows Event Log)
- Suspicious Child Process for hh.exe (Sysmon)
- Suspicious Child Process for hh.exe (Windows Event Log)
- Suspicious Child Process for mshta.exe (Sysmon)
- Suspicious Child Process for mshta.exe (Windows Event Log)
- Suspicious Execution via Microsoft Common Console (Sysmon)
- Suspicious Execution via Microsoft Common Console (Windows Event Log)
- Suspicious IcedID Rundll32 Cmdline
- Suspicious mshta child process
- Suspicious mshta spawn
- Suspicious Parent Process for msiexec.exe (Sysmon)
- Suspicious Parent Process for msiexec.exe (Windows Event Log)
- Suspicious reCAPTCHA Command Line (PowerShell)
- Suspicious reCAPTCHA Command Line (Sysmon)
- Suspicious Regsvr32 Register Suspicious Path
- Suspicious Rundll32 dllregisterserver
- Suspicious Rundll32 no Command Line Arguments
- Suspicious Rundll32 PluginInit
- Suspicious Rundll32 StartW
- SyncAppvPublishingServer Execution (Windows Event Log)
- UAC Bypass MMC Load Unsigned Dll
- UAC Bypass With Colorui COM Object
- Uninstall App Using MsiExec
- Verclsid CLSID Execution
- Wbemprox COM Object Execution
- Windows Advanced Installer MSIX with AI_STUBS Execution
- Windows Application Whitelisting Bypass Attempt via Rundll32
- Windows AppLocker Block Events
- Windows AppLocker Execution from Uncommon Locations
- Windows AppLocker Privilege Escalation via Unauthorized Bypass
- Windows AppLocker Rare Application Launch Detection
- Windows Binary Proxy Execution Mavinject DLL Injection
- Windows BitLockerToGo Process Execution
- Windows BitLockerToGo with Network Activity
- Windows Diskshadow Proxy Execution
- Windows DotNet Binary in Non Standard Path
- Windows Execute Arbitrary Commands with MSDT
- Windows Execution of Microsoft MSC File In Suspicious Path
- Windows GrimResource - MMC Process Accessing APDS DLL
- Windows HTTP Network Communication From MSIExec
- Windows InstallUtil Credential Theft
- Windows InstallUtil in Non Standard Path
- Windows InstallUtil Remote Network Connection
- Windows InstallUtil Uninstall Option
- Windows InstallUtil URL in Command Line
- Windows IOBit Unlocker Extension DLL Registration via Regsvr32
- Windows LOLBAS Executed As Renamed File
- Windows LOLBAS Executed Outside Expected Path
- Windows Mock Trusted Directory MSC File Creation
- Windows MSC EvilTwin Directory Path Manipulation
- Windows Mshta Execution In Registry
- Windows MSHTA Writing to World Writable Path
- Windows MSI Rollback Script Deleted By Non-Msiexec Process
- Windows MSIExec DLLRegisterServer
- Windows MsiExec HideWindow Rundll32 Execution
- Windows MSIExec Remote Download
- Windows MSIExec Spawn Discovery Command
- Windows MSIExec Spawn WinDBG
- Windows MSIExec Unregister DLLRegisterServer
- Windows Odbcconf Hunting
- Windows Odbcconf Load DLL
- Windows Odbcconf Load Response File
- Windows Process Writing File to World Writable Path
- Windows Proxy Execution of .NET Utilities via Scripts
- Windows Rasautou DLL Execution
- Windows Regsvr32 Renamed Binary
- Windows Rundll32 Apply User Settings Changes
- Windows Rundll32 Load DLL in Temp Dir
- Windows Rundll32 with Non-Standard File Extension
- Windows System Binary Proxy Execution Compiled HTML File Decompile
- Windows System Script Proxy Execution Syncappvpublishingserver
- Windows Unusual Process Load Mozilla NSS-Mozglue Module
- wuauclt.exe Network Connection (Sysmon)
- wuauclt.exe Network Connection (Windows Event Log)