System Binary Proxy Execution T1218

Tactic: Stealth

Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Several Microsoft signed binaries that are default on Windows installations can be used to proxy execution of other files or commands.

Events covered

39 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 7Image loaded
SysmonEvent ID 8CreateRemoteThread
SysmonEvent ID 10ProcessAccess
SysmonEvent ID 11FileCreate
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
SysmonEvent ID 22DNSEvent (DNS query)
SysmonEvent ID 23FileDelete (File Delete archived)
SysmonEvent ID 26FileDeleteDetected (File Delete logged)
SysmonEvent ID 29FileExecutableDetected
Security-AuditingEvent ID 4663An attempt was made to access an object.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 5156The Windows Filtering Platform has permitted a connection.
Defender-DeviceEventsCreateRemoteThreadApiCallCreateRemoteThread API call
Defender-DeviceEventsClrUnbackedModuleLoadedCLR unbacked module loaded
Defender-DeviceEventsNtAllocateVirtualMemoryRemoteApiCallRemote virtual memory allocation (NtAllocateVirtualMemory)
Defender-DeviceEventsMemoryRemoteProtectRemote virtual memory protection change
Defender-DeviceEventsNtMapViewOfSectionRemoteApiCallRemote section map (NtMapViewOfSection)
Defender-DeviceEventsQueueUserApcRemoteApiCallRemote APC queued (QueueUserApc)
Defender-DeviceEventsSetThreadContextRemoteApiCallRemote thread context change (SetThreadContext)
Defender-DeviceEventsReadProcessMemoryApiCallReadProcessMemory API call
Defender-DeviceFileEventsanyFile activity
Defender-DeviceFileEventsFileCreatedFile created
Defender-DeviceFileEventsFileRenamedFile renamed
Defender-DeviceImageLoadEventsanyImage load
Defender-DeviceImageLoadEventsImageLoadedImage loaded
Defender-DeviceNetworkEventsanyNetwork activity
Defender-DeviceProcessEventsanyProcess activity
Defender-DeviceProcessEventsProcessCreatedProcess created
ESFexecProcess Execution
ESFcreateFile or Directory Create
ESFwriteFile Write
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
MsiInstallerEvent ID 1040Beginning a Windows Installer transaction: %0
MsiInstallerEvent ID 1042Ending a Windows Installer transaction: %0

Authoring guide

These 672 rules share fields, values, and exclusions.

Fields filtered most (141 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine313contains 199, regex_match 66, in 27, wildcard 22, ends_with 21, eq 5, match 5, is_not_null 4, starts_with 4, is_null 3, length_compare 1, ne 1http://, https://, .dll, (?i)\w+tps?://\S+\.msi, ftp://
process_name256eq 200, regex_match 28, in 21, ne 5, wildcard 5, is_not_null 3, ends_with 1, starts_with 1rundll32.exe, cmd.exe, cscript.exe, mshta.exe, msiexec.exe
Image246ends_with 203, wildcard 20, contains 13, starts_with 12, eq 10, is_not_null 7, in 1, regex_match 1\rundll32.exe, \cmd.exe, \regsvr32.exe, \cscript.exe, \mshta.exe
OriginalFileName212eq 207, in 4, contains 1, is_null 1, wildcard 1rundll32.exe, mshta.exe, regsvr32.exe, cscript.exe, installutil.exe
EventType127eq 116, in 14, ne 10, starts_with 2start, exec, creation, deletion, connection_attempted
EventID119eq 116, in 34688, 1, 4104, 4103, 7
parent_process_name117eq 86, regex_match 19, in 11, starts_with 3, contains 2, wildcard 1explorer.exe, msiexec.exe, cmd.exe, mshta.exe, mmc.exe
ParentImage95ends_with 60, eq 27, starts_with 6, is_not_null 5, contains 4, wildcard 4, in 1, is_null 1\cmd.exe, \cscript.exe, \mshta.exe, \excel.exe, \rundll32.exe
event.type92eq 91, ne 1start, creation, change, deletion
host.os.type83eq 83
process.args65eq 42, wildcard 19, starts_with 13, contains 5, in 5, ends_with 3-c, -i, -q, .msc, --command
Type42eq 42
ParentCommandLine29contains 15, regex_match 4, wildcard 4, is_not_null 3, ends_with 2, eq 1, in 1, is_null 1, length_compare 1 -embedding, /processid:{3e000d72-a845-4cd9-bd83-80c07c3b881f}, /processid:{3e5fc7f9-9a51-4367-9063-a120244fbec7}, /processid:{bd54c901-076b-434e-b6c7-17c531f4ab41}, #568
process.parent.args27eq 25, ends_with 2, starts_with 1, wildcard 1-embedding, /v, .msc, /V, *$*$*$*$*$*
TargetFilename26ends_with 9, contains 5, starts_with 5, wildcard 5, in 4, eq 1*\\windows\\pla\\reports\\*, *\\windows\\pla\\rules\\*, .dll, .exe, .sed

Top indicator values (4013 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypeeq
start
92391
EventTypeeq
exec
17576
event.typeeq
start
871078
process_nameeq
rundll32.exe
72126
process_nameeq
mshta.exe
4484
process_nameeq
powershell.exe
42184
process_nameeq
regsvr32.exe
4073
process_nameeq
wscript.exe
3583
process_nameeq
msiexec.exe
3246
process_nameeq
cmd.exe
31121
process_nameeq
cscript.exe
3067
process_nameeq
installutil.exe
2637
process_nameeq
certutil.exe
1844
process_nameeq
regsvcs.exe
1823
process_nameeq
regasm.exe
1726
OriginalFileNameeq
rundll32.exe
4678
OriginalFileNameeq
regsvr32.exe
2337
OriginalFileNameeq
mshta.exe
2040
EventIDeq
4688
45317
EventIDeq
1
36241
EventIDeq
4104
17269
Imageends_with
\rundll32.exe
3894
Imageends_with
\regsvr32.exe
2864
Imageends_with
\mshta.exe
2466
Imageends_with
\cmd.exe
19130
Imageends_with
\powershell.exe
19179
Imageends_with
\cscript.exe
1872
Imageends_with
\pwsh.exe
18165
Imageends_with
\wscript.exe
1874
parent_process_nameeq
explorer.exe
2051

Exclusions (2315 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.code_signature.trustedeq
true
22
process_nameeq
rundll32.exe
21
process_nameeq
regsvr32.exe
15
process_nameeq
cmd.exe
13
process_nameeq
powershell.exe
12
process_nameeq
wscript.exe
12
dest_ipcidr_match
10.0.0.0/8
16
dest_ipcidr_match
127.0.0.0/8
16
dest_ipcidr_match
169.254.0.0/16
16
dest_ipcidr_match
172.16.0.0/12
16
dest_ipcidr_match
192.168.0.0/16
16
user.ideq
s-1-5-18
14
process.argsstarts_with
?:\Program Files (x86)\
13
process.argsstarts_with
?:\Program Files\
13
Imagewildcard
?:\program files (x86)\*.exe
9

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 255 rules

Elastic 209 rules

Splunk 200 rules

Kusto 8 rules