System Binary Proxy Execution T1218
Tactic: Stealth
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Several Microsoft signed binaries that are default on Windows installations can be used to proxy execution of other files or commands.
Events covered
39 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 672 rules share fields, values, and exclusions.
Fields filtered most (141 distinct)
These fields appear most often in rule filters.
Top indicator values (4013 distinct)
These values appear most often in rule predicates.
Exclusions (2315 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 255 rules
- Abusing Print Executable
- AddinUtil.EXE Execution From Uncommon Directory
- AgentExecutor PowerShell Execution
- APT29 2018 Phishing Campaign CommandLine Indicators
- APT29 2018 Phishing Campaign File Indicators
- Arbitrary Command Execution Using WSL
- Arbitrary DLL or Csproj Code Execution Via Dotnet.EXE
- Arbitrary File Download Via IMEWDBLD.EXE
- Arbitrary File Download Via MSEDGE_PROXY.EXE
- Arbitrary File Download Via MSOHTMED.EXE
- Arbitrary File Download Via MSPUB.EXE
- Arbitrary File Download Via PresentationHost.EXE
- Arbitrary File Download Via Squirrel.EXE
- Arbitrary MSI Download Via Devinit.EXE
- Atbroker Registry Change
- BaaUpdate.exe Suspicious DLL Load
- Bad Opsec Defaults Sacrificial Processes With Improper Arguments
- Binary Proxy Execution Via Dotnet-Trace.EXE
- BitLockerTogo.EXE Execution
- Bypass UAC via CMSTP
- CMSTP Execution Process Access
- CMSTP Execution Process Creation
- CMSTP Execution Registry Event
- CMSTP UAC Bypass via COM Object Access
- CobaltStrike Load by Rundll32
- Code Execution via Pcwutl.dll
- COM Object Execution via Xwizard.EXE
- Control Panel Items
- Created Files by Microsoft Sync Center
- Csc.EXE Execution Form Potentially Suspicious Parent
- Curl Download And Execute Combination
- DeviceCredentialDeployment Execution
- Devtoolslauncher.exe Executes Specified Binary
- Diskshadow Child Process Spawned
- Diskshadow Script Mode - Execution From Potential Suspicious Location
- Diskshadow Script Mode - Uncommon Script Extension Execution
- Diskshadow Script Mode Execution
- DLL Call by Ordinal Via Rundll32.EXE
- DLL Execution via Rasautou.exe
- DLL Loaded From Suspicious Location Via Cmspt.EXE
- DLL Loaded via CertOC.EXE
- Dllhost.EXE Initiated Network Connection To Non-Local IP Address
- DllUnregisterServer Function Call Via Msiexec.EXE
- DNS Query Request By Regsvr32.EXE
- Driver/DLL Installation Via Odbcconf.EXE
- Equation Group DLL_U Export Function Load
- EvilNum APT Golden Chickens Deployment Via OCX Files
- Execute Files with Msdeploy.exe
- Execute Pcwrun.EXE To Leverage Follina
- Execution DLL of Choice Using WAB.EXE
- Execution via stordiag.exe
- Execution via WorkFolders.exe
- File Download Using ProtocolHandler.exe
- File Download Via InstallUtil.EXE
- File Download Via Windows Defender MpCmpRun.EXE
- Fireball Archer Install
- Gpscript Execution
- HackTool - CACTUSTORCH Remote Thread Creation
- HackTool - F-Secure C3 Load by Rundll32
- HackTool - RedMimicry Winnti Playbook Execution
- HH.EXE Execution
- HH.EXE Initiated HTTP Network Connection
- Hidden Flag Set On File/Directory Via Chflags - MacOS
- HTML Help HH.EXE Suspicious Child Process
- IcedID Malware Suspicious Single Digit DLL Execution Via Rundll32
- Ie4uinit Lolbin Use From Invalid Path
- Import LDAP Data Interchange Format File Via Ldifde.EXE
- Indirect Command Execution By Program Compatibility Wizard
- InfDefaultInstall.exe .inf Execution
- Insensitive Subfolder Search Via Findstr.EXE
- Kapeka Backdoor Execution Via RunDLL32.EXE
- Kapeka Backdoor Loaded Via Rundll32.EXE
- Legitimate Application Dropped Archive
- Legitimate Application Dropped Executable
- Legitimate Application Dropped Script
- Legitimate Application Writing Files In Uncommon Location
- Lolbin Runexehelper Use As Proxy
- Lolbin Unregmp2.exe Use As Proxy
- Malicious PE Execution by Microsoft Visual Studio Debugger
- Malicious Windows Script Components File Execution by TAEF Detection
- Mavinject Inject DLL Into Running Process
- Microsoft Sync Center Suspicious Network Connections
- Microsoft Workflow Compiler Execution
- MMC Executing Files with Reversed Extensions Using RTLO Abuse
- MMC Loading Script Engines DLLs
- MpiExec Lolbin
- MSDT Execution Via Answer File
- MSHTA Execution with Suspicious File Extensions
- MSI Installation From Web
- Msiexec Quiet Installation
- MsiExec Web Install
- Msiexec.EXE Initiated Network Connection Over HTTP
- Network Connection Initiated By AddinUtil.EXE
- Network Connection Initiated By Regsvr32.EXE
- New Capture Session Launched Via DXCap.EXE
- New DLL Registered Via Odbcconf.EXE
- New Self Extracting Package Created Via IExpress.EXE
- NotPetya Ransomware Activity
- Obfuscated PowerShell MSI Install via WindowsInstaller COM
- Odbcconf.EXE Suspicious DLL Location
- OneNote.EXE Execution of Malicious Embedded Scripts
- OpenWith.exe Executes Specified Binary
- Outbound Network Connection Initiated By Cmstp.EXE
- Outbound Network Connection To Public IP Via Winlogon
- Potential Application Whitelisting Bypass via Dnx.EXE
- Potential APT-C-12 BlueMushroom DLL Load Activity Via Regsvr32
- Potential Arbitrary File Download Via Cmdl32.EXE
- Potential Baby Shark Malware Activity
- Potential Binary Impersonating Sysinternals Tools
- Potential Binary Proxy Execution Via Cdb.EXE
- Potential Binary Proxy Execution Via VSDiagnostics.EXE
- Potential Bumblebee Remote Thread Creation
- Potential Compromised 3CXDesktopApp Execution
- Potential Compromised 3CXDesktopApp Update Activity
- Potential Devil Bait Malware Reconnaissance
- Potential DLL Sideloading Activity Via ExtExport.EXE
- Potential DLL Sideloading Using Coregen.exe
- Potential Emotet Rundll32 Execution
- Potential EmpireMonkey Activity
- Potential Exploitation of RCE Vulnerability CVE-2025-33053
- Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Image Load
- Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Process Access
- Potential File Download Via MS-AppInstaller Protocol Handler
- Potential LethalHTA Technique Execution
- Potential Mpclient.DLL Sideloading Via OfflineScannerShell.EXE Execution
- Potential NTLM Coercion Via Certutil.EXE
- Potential Password Spraying Attempt Using Dsacls.EXE
- Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE
- Potential PowerShell Execution Via DLL
- Potential Provisioning Registry Key Abuse For Binary Proxy Execution
- Potential Provisioning Registry Key Abuse For Binary Proxy Execution - REG
- Potential Provlaunch.EXE Binary Proxy Execution Abuse
- Potential Proxy Execution Via Explorer.EXE From Shell Process
- Potential Raspberry Robin CPL Execution Activity
- Potential Register_App.Vbs LOLScript Abuse
- Potential Regsvr32 Commandline Flag Anomaly
- Potential RemoteFXvGPUDisablement.EXE Abuse
- Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell Module
- Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell ScriptBlock
- Potential Suspicious Child Process Of 3CXDesktopApp
- Potentially Over Permissive Permissions Granted Using Dsacls.EXE
- Potentially Suspicious Cabinet File Expansion
- Potentially Suspicious Child Process Of DiskShadow.EXE
- Potentially Suspicious Child Process Of Regsvr32
- Potentially Suspicious Child Process Of VsCode
- Potentially Suspicious Child Processes Spawned by ConHost
- Potentially Suspicious CMD Shell Output Redirect
- Potentially Suspicious DLL Registered Via Odbcconf.EXE
- Potentially Suspicious Execution Of Regasm/Regsvcs From Uncommon Location
- Potentially Suspicious Execution Of Regasm/Regsvcs With Uncommon Extension
- Potentially Suspicious Mofcomp Execution
- Potentially Suspicious Regsvr32 HTTP IP Pattern
- Potentially Suspicious Regsvr32 HTTP/FTP Pattern
- Potentially Suspicious Rundll32 Activity
- Potentially Suspicious Rundll32.EXE Execution of UDL File
- Potentially Suspicious Self Extraction Directive File Created
- Potentially Suspicious Wuauclt Network Connection
- PowerShell MSI Install via WindowsInstaller COM From Remote Location
- PowerShell WMI Win32_Product Install MSI
- Process Access via TrolleyExpress Exclusion
- Process Memory Dump Via Dotnet-Dump
- Process Proxy Execution Via Squirrel.EXE
- Program Executed Using Proxy/Local Command Via SSH.EXE
- Proxy Execution Via Wuauclt.EXE
- RegAsm.EXE Execution Without CommandLine Flags or Files
- RegAsm.EXE Initiating Network Connection To Public IP
- REGISTER_APP.VBS Proxy Execution
- Regsvr32 DLL Execution With Suspicious File Extension
- Regsvr32 Execution From Highly Suspicious Location
- Regsvr32 Execution From Potential Suspicious Location
- Regsvr32.EXE Calling of DllRegisterServer Export Function Implicitly
- Remote CHM File Download/Execution Via HH.EXE
- Remote File Download Via Findstr.EXE
- Remote Thread Creation Via PowerShell In Uncommon Target
- RemoteFXvGPUDisablement Abuse Via AtomicTestHarnesses
- Remotely Hosted HTA File Executed Via Mshta.EXE
- Renamed Mavinject.EXE Execution
- Renamed MegaSync Execution
- Renamed ZOHO Dctask64 Execution
- Response File Execution Via Odbcconf.EXE
- Rhadamanthys Stealer Module Launch Via Rundll32.EXE
- Rundll32 Execution With Uncommon DLL Extension
- Rundll32 InstallScreenSaver Execution
- Rundll32 Internet Connection
- RunDLL32 Spawning Explorer
- Rundll32 UNC Path Execution
- Rundll32.EXE Calling DllRegisterServer Export Function Explicitly
- Scheduled Task Creation with Curl and PowerShell Execution Combo
- SCR File Write Event
- ScreenSaver Registry Key Set
- Scripting/CommandLine Process Spawned Regsvr32
- Sdiagnhost Calling Suspicious Child Process
- Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location
- Self Extraction Directive File Created In Potentially Suspicious Location
- Sensitive File Dump Via Print.EXE
- Shell32 DLL Execution in Suspicious Directory
- Sofacy Trojan Loader Activity
- Suspicious AddinUtil.EXE CommandLine Execution
- Suspicious AgentExecutor PowerShell Execution
- Suspicious BitLocker Access Agent Update Utility Execution
- Suspicious Child Process Of BgInfo.EXE
- Suspicious Control Panel DLL Load
- Suspicious Csi.exe Usage
- Suspicious DLL Loaded via CertOC.EXE
- Suspicious DotNET CLR Usage Log Artifact
- Suspicious Driver/DLL Installation Via Odbcconf.EXE
- Suspicious HH.EXE Execution
- Suspicious JavaScript Execution Via Mshta.EXE
- Suspicious Microsoft Office Child Process
- Suspicious MSDT Parent Process
- Suspicious MSHTA Child Process
- Suspicious MsiExec Embedding Parent
- Suspicious Msiexec Execute Arbitrary DLL
- Suspicious Msiexec Quiet Install From Remote Location
- Suspicious Provlaunch.EXE Child Process
- Suspicious Regsvr32 Execution From Remote Share
- Suspicious Response File Execution Via Odbcconf.EXE
- Suspicious Rundll32 Activity Invoking Sys File
- Suspicious Rundll32 Execution With Image Extension
- Suspicious Rundll32 Setupapi.dll Activity
- Suspicious ShellExec_RunDLL Call Via Ordinal
- Suspicious Speech Runtime Binary Child Process
- Suspicious Vsls-Agent Command With AgentExtensionPath Load
- Suspicious WMIC Execution Via Office Process
- Suspicious WmiPrvSE Child Process
- Suspicious ZipExec Execution
- SyncAppvPublishingServer Bypass Powershell Restriction - PS Module
- SyncAppvPublishingServer Execute Arbitrary PowerShell Code
- SyncAppvPublishingServer Execution to Bypass Powershell Restriction
- SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code
- Time Travel Debugging Utility Usage
- Time Travel Debugging Utility Usage - Image
- Uncommon Assistive Technology Applications Execution Via AtBroker.EXE
- Uncommon AddinUtil.EXE CommandLine Execution
- Uncommon Child Process Of AddinUtil.EXE
- Uncommon Child Process Of Appvlp.EXE
- Uncommon Child Process Of BgInfo.EXE
- Uncommon Child Process Of Defaultpack.EXE
- Uncommon Child Process Of Setres.EXE
- Uncommon Child Process Spawned By Odbcconf.EXE
- Uncommon Link.EXE Parent Process
- Unsigned DLL Loaded by Windows Utility
- Use of Scriptrunner.exe
- Use Of The SFTP.EXE Binary As A LOLBIN
- Use of VisualUiaVerifyNative.exe
- Verclsid.exe Runs COM Object
- Visual Studio NodejsTools PressAnyKey Arbitrary Binary Execution
- Visual Studio NodejsTools PressAnyKey Renamed Execution
- Windows MSIX Package Support Framework AI_STUBS Execution
- Windows Shell/Scripting Processes Spawning Suspicious Programs
- Winrs Local Command Execution
- Wlrmdr.EXE Uncommon Argument Or Child Process
- WSL Child Process Anomaly
- XBAP Execution From Uncommon Locations Via PresentationHost.EXE
- ZxShell Malware
Elastic 209 rules
- BCDEdit Safe Mode Command Execution
- Binary Proxy Execution via AppVLP
- Binary Proxy Execution via Pester
- Binary Proxy Execution via Rundll32
- Binary Proxy Execution via Runexehelper
- Binary Proxy Execution via TTDInject
- Binary Proxy Execution via Windows OpenSSH
- Command and Scripting Interpreter via Windows Scripts
- Command Shell Activity Started via RunDLL32
- Command Shell Activity Started via RunDLL32
- Connection to Dynamic DNS Provider by a Signed Binary Proxy
- Connection to WebService by a Signed Binary Proxy
- Control Panel Process with Unusual Arguments
- Control Panel Process with Unusual Arguments
- Creation of SettingContent-ms Files
- Curl or Wget Egress Network Connection via LoLBin
- Delayed Execution via Ping
- Disk Image Download and Mount via Hdiutil
- DLL Control Panel Items Registry Modification
- DLL Dropped by MSIEXEC followed by SideLoad
- DLL Execution via Visual Studio Live Share
- DLL Injection via MavInject Utility
- Dynamic Linker (ld.so) Creation
- Encoded Powershell Execution via MsiExec
- Evasion via Device Credential Deployment
- Execution from a Remote Working Directory
- Execution from Unusual Directory
- Execution from Unusual Directory - Command Line
- Execution from ZIP File via Explorer
- Execution of a Binary Dropped via Microsoft BSDTAR Archive Tool
- Execution of a Downloaded Windows Script
- Execution of a Downloaded Windows Script via Explorer
- Execution of a File Downloaded via Windows OpenSSH
- Execution of a File Written by a Signed Binary Proxy
- Execution of a Windows Script Downloaded from the Internet
- Execution of a Windows Script Downloaded via a LOLBIN
- Execution of a Windows Script File Written by a Suspicious Process
- Execution of COM object via Xwizard
- Execution of Commonly Abused Utilities via Explorer Trampoline
- Execution of Persistent Suspicious Program
- Execution via a Suspicious WMI Client
- Execution via DCOM Excel Application
- Execution via GitHub Actions Runner
- Execution via Internet Explorer Exporter
- Execution via Microsoft DotNet ClickOnce Host
- Execution via MsiExec DownloadAndExecute CustomAction
- Execution via OpenClaw Agent
- Execution via Outlook Application COM Object
- Execution via Program Compatibility Assistant
- Execution via Renamed Signed Binary Proxy
- Execution via SyncAppvPublishingServer
- Execution via Windows Command Debugging Utility
- Execution via Windows Command Line Debugging Utility
- Execution via Windows Installer Transforms
- File Execution via Microsoft HTML Help
- File or Directory Deletion Command
- File with Suspicious Extension Downloaded
- Host Detected with Suspicious Windows Process(es)
- ImageLoad of a File dropped via SMB
- ImageLoad via Windows Update Auto Update Client
- Incoming DCOM Lateral Movement via MSHTA
- Incoming DCOM Lateral Movement with MMC
- Inhibit System Recovery via Renamed Utilities
- Inhibit System Recovery via Signed Binary Proxy
- InstallUtil Activity
- InstallUtil Process Making Network Connections
- Library Load of a File Written by a Signed Binary Proxy
- Microsoft Build Engine Started by a Script Process
- Microsoft Management Console File from Unusual Path
- Mshta Making Network Connections
- MSI Rollback Script File by Unusual Process
- Msiexec Execution via a Windows Script Interpreter
- MsiExec Service Child Process With Network Connection
- Netcat Reverse Shell via Busybox
- Network Activity to a Suspicious Top Level Domain
- Network Connection via Certutil
- Network Connection via Compiled HTML File
- Network Connection via Registration Utility
- Network Connection via Signed Binary
- Network Connection via Startup Item
- Oversized Windows Script Execution
- Parent Process Detected with Suspicious Windows Process(es)
- Persistence via a Windows Installer
- Potential Command and Control via Internet Explorer
- Potential Credential Access via Renamed COM+ Services DLL
- Potential Credential Access via Windows Utilities
- Potential CVE-2025-33053 Exploitation
- Potential CVE-2025-33053 Exploitation
- Potential Defense Evasion via CMSTP.exe
- Potential Escalation via Vulnerable MSI Repair
- Potential Evasion via ASP.NET Compiler
- Potential Evasion via dotNET Framework Installation Utility
- Potential Evasion via Intel GfxDownloadWrapper
- Potential Execution via FileFix Phishing Attack
- Potential Fake CAPTCHA Phishing Attack
- Potential File Transfer via Certreq
- Potential Local NTLM Relay via HTTP
- Potential Privilege Escalation via SUID/SGID Proxy Execution
- Potential Privilege Escalation via SUID/SGID Proxy Execution
- Potential Protocol Tunneling via Yuze
- Potential Proxy Execution via Crash
- Potential Proxy Execution via PHP
- Potential Proxy Execution via Pidstat
- Potential Proxy Execution via Run-parts
- Potential Proxy Execution via Sed
- Potential Proxy Execution via Split
- Potential Proxy Execution via Sysctl
- Potential Proxy Execution via Systemd-run
- Potential Proxy Execution via Tcpdump
- Potential Remote Execution via IMsiServer
- Potential Remote File Execution via MSIEXEC
- Potential Remote Install via MsiExec
- Potential TCC Bypass via Electron Web Inspector API
- Potentially Suspicious Process Started via tmux or screen
- PowerShell Execution from WinGet Configuration Remoting Server
- Privilege Escalation via Windows Installer Hijack
- Process Activity via Compiled HTML File
- Proxy Shell Execution via Busybox
- Rare Connection to WebDAV Target
- Regsvr32 Scriptlet Execution
- Regsvr32 with Unusual Arguments
- Remote File Execution via MSIEXEC
- Remote MSI Package Installation via MSIEXEC
- Rundll32 or Regsvr32 Loaded a DLL from Unbacked Memory
- RunDLL32 with Unusual Arguments
- RunDLL32/Regsvr32 Loads a DLL Downloaded via BITS
- RunDLL32/Regsvr32 Loads Dropped Executable
- Script Execution via APDS XSS Injection
- Script Execution via Microsoft HTML Application
- Script Execution via Microsoft HTML Application
- Script File Written by Microsoft Office Process
- Scriptlet Execution via CMSTP
- Scriptlet Execution via Rundll32
- Service Control Spawned via Script Interpreter
- Shared Object Load via LoLBin
- Shell Execution via Elastic Endpoint
- Signed Proxy Execution via MS Work Folders
- Suspicious .NET Code Compilation
- Suspicious Activity from a Control Panel Applet
- Suspicious API call via a Windows Installer Module
- Suspicious Child Process from WinGet Configuration Remoting Server
- Suspicious Child Process via Azure VM CustomScript Extension
- Suspicious Command and Control via Internet Explorer
- Suspicious Command Execution via Busybox Proxy
- Suspicious Control Panel DLL Loaded by Explorer
- Suspicious DLLRegisterServer Execution via MSIEXEC
- Suspicious DNS Query by MSIEXEC
- Suspicious Execution from a Mounted Device
- Suspicious Execution from a Mounted Device
- Suspicious Execution from VS Code Extension
- Suspicious Execution via Compiled HTML File
- Suspicious Execution via DCOM
- Suspicious Execution via DotNet Remoting
- Suspicious Execution via IHxHelpPaneServer
- Suspicious Execution via Microsoft Common Console
- Suspicious Execution via MSIEXEC
- Suspicious Execution via ShellBrowserWindow/ShellWindow COM
- Suspicious Explorer Child Process
- Suspicious File Rename by an Unusual Process
- Suspicious ImageLoad from an ISO Mounted Device
- Suspicious ImageLoad via ODBC Driver Configuration Program
- Suspicious ImageLoad via Windows CertOC
- Suspicious ImageLoad via Windows Update Auto Update Client
- Suspicious JetBrains TeamCity Child Process
- Suspicious Managed Code Hosting Process
- Suspicious Memory Mapping from a Windows Installer
- Suspicious Microsoft Diagnostics Wizard Execution
- Suspicious Microsoft HTML Application Child Process
- Suspicious Microsoft HTML Help Descendant
- Suspicious MS Office Child Process
- Suspicious MS Outlook Child Process
- Suspicious MsiExec Child Process
- Suspicious PDF Reader Child Process
- Suspicious Registry Modification via WMI
- Suspicious ScreenConnect Client Child Process
- Suspicious Script Object Execution
- Suspicious Shell Execution via Velociraptor
- Suspicious SolarWinds Web Help Desk Java Module Load or Child Process
- Suspicious Startup Persistence via a Windows Installer
- Suspicious Troubleshooting Pack Cabinet Execution
- Suspicious Windows Command Shell Arguments
- Suspicious Windows Component Object Model via DLLHOST
- Suspicious Windows Schedule Child Process
- Suspicious Windows Script Downloaded from the Internet
- Suspicious WMIC XSL Script Execution
- System Binary Proxy Execution via ld.so
- System Binary Proxy Execution via ScriptRunner
- UAC Bypass Attempt via Elevated COM Internet Explorer Add-On Installer
- UAC Bypass via Windows Firewall Snap-In Hijack
- Unsigned DLL loaded by Rundll32 via COM
- Unusual Child Processes of RunDLL32
- Unusual DLL Extension Loaded by Rundll32 or Regsvr32
- Unusual Execution via Microsoft Common Console File
- Unusual Network Activity from a Windows System Binary
- Unusual Network Connection via DllHost
- Unusual Network Connection via RunDLL32
- Unusual Network Connection via RunDLL32
- Unusual Process Network Connection
- Unusual Process Spawned by a Host
- Unusual Process Spawned by a Parent Process
- Unusual Process Spawned by a User
- User Detected with Suspicious Windows Process(es)
- Velociraptor Suspicious Shell Execution
- Windows Installer Execution via Explorer
- Windows Installer via Windows Script
- Windows Installer with Suspicious Properties
- Windows Script Executed From a Suspicious Path
- Windows Script Execution via MMC Console File
- Windows Server Update Service Spawning Suspicious Processes
Splunk 200 rules
- .msc Executed from Unusual Location (Sysmon)
- .msc Executed from Unusual Location (Windows Event Log)
- 3CXDesktopApp.exe Execution (Sysmon)
- 3CXDesktopApp.exe Execution (Windows Event Log)
- ATBroker.exe Execution (PowerShell)
- ATBroker.exe Execution (Sysmon)
- ATBroker.exe Execution (Windows Event Log)
- Bash -c Execution - Windows (Sysmon)
- Bash -c Execution - Windows (Windows Event Log)
- Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI
- Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download
- Cisco NVM - Suspicious Network Connection From Process With No Args
- CMLUA Or CMSTPLUA UAC Bypass
- Cmstp Execution (Sysmon)
- Cmstp Execution (Windows Event Log)
- Control Loading from World Writable Directory
- Control Panel Abuse (Sysmon)
- Control Panel Abuse (Windows Event Log)
- Control_RunDLL Call from Command Line (Sysmon)
- Control_RunDLL Call from Command Line (Windows Event Log)
- Detect HTML Help Renamed
- Detect HTML Help Spawn Child Process
- Detect HTML Help URL in Command Line
- Detect HTML Help Using InfoTech Storage Handlers
- Detect mshta inline hta execution
- Detect mshta renamed
- Detect MSHTA Url in Command Line
- Detect Regasm Spawning a Process
- Detect Regasm with Network Connection
- Detect Regasm with no Command Line Arguments
- Detect Regsvcs Spawning a Process
- Detect Regsvcs with Network Connection
- Detect Regsvcs with No Command Line Arguments
- Detect Regsvr32 Application Control Bypass
- Detect Rundll32 Inline HTA Execution
- DLL Called with RS32 (PowerShell)
- DLL Called with RS32 (Sysmon)
- DLL Called with RS32 (Windows Event Log)
- DLL Called with Uncommon Function (PowerShell)
- DLL Called with Uncommon Function (Sysmon)
- DLL Called with Uncommon Function (Windows Event Log)
- DLL Execution from Uncommon Process (PowerShell)
- DLL Execution from Uncommon Process (Sysmon)
- DLL Execution from Uncommon Process (Windows Event Log)
- DLLRegisterServer Called from Command Line (PowerShell)
- DLLRegisterServer Called from Command Line (Sysmon)
- DLLRegisterServer Called from Command Line (Windows Event Log)
- DNX.exe Proxy Execution (Windows Event Log)
- Dotnet.exe Execution (Windows Event Log)
- Driver as Command Parameter (Windows Event Log)
- Dxcap Proxy Execution (Windows Event Log)
- Executable Process from Suspicious Folder (PowerShell)
- Executable Process from Suspicious Folder (Sysmon)
- Executable Process from Suspicious Folder (Windows Event Log)
- Group Policy Editor Execution (PowerShell)
- Group Policy Editor Execution (Sysmon)
- Group Policy Editor Execution (Windows Event Log)
- hh.exe Execution (PowerShell)
- hh.exe Execution (Sysmon)
- hh.exe Execution (Windows Event Log)
- hh.exe Remote File Execution (PowerShell)
- hh.exe Remote File Execution (Sysmon)
- hh.exe Remote File Execution (Windows Event Log)
- IIS Worker (W3WP) Spawn Command Line (Windows Event Log)
- LOLBAS With Network Traffic
- Malicious InProcServer32 Modification
- Mavinject Execution (Sysmon)
- Mavinject Execution (Windows Event Log)
- Mmc LOLBAS Execution Process Spawn
- Mshta spawning Rundll32 OR Regsvr32 Process
- MSHTA.exe execution (PowerShell)
- MSHTA.exe execution (Sysmon)
- MSHTA.exe execution (Windows Event Log)
- mshta.exe File Download (PowerShell)
- mshta.exe File Download (Sysmon)
- mshta.exe File Download (Windows Event Log)
- MSI Installation via Appcert (PowerShell)
- MSI Installation via Appcert (Sysmon)
- MSI Installation via Appcert (Windows Event Log)
- Msiexec Abuse (Sysmon)
- Msiexec Abuse (Windows Event Log)
- MSIExec Install MSI File (Sysmon)
- MSIExec Install MSI File (Windows Event Log)
- MSIExec.exe Execution (Sysmon)
- MSIExec.exe Execution (Windows Event Log)
- Nslookup Execution (Windows Event Log)
- Possible Lateral Movement PowerShell Spawn
- Potential Sysinternals Tool Execution (PowerShell)
- Potential Sysinternals Tool Execution (Sysmon)
- Potential Sysinternals Tool Execution (Windows Event Log)
- Process Creation Using Sysnative Folder (Sysmon)
- Process Creation Using Sysnative Folder (Windows Event Log)
- regsvr32 Execution (PowerShell)
- regsvr32 Execution (Sysmon)
- regsvr32 Execution (Windows Event Log)
- regsvr32 Referencing Unusual Paths (Sysmon)
- regsvr32 Referencing Unusual Paths (Windows Event Log)
- Regsvr32 Silent and Install Param Dll Loading
- Remote .msi Installation (PowerShell)
- Remote .msi Installation (PowerShell)
- Remote .msi Installation (Sysmon)
- Remote .msi Installation (Sysmon)
- Remote .msi Installation (Windows Event Log)
- Remote .msi Installation (Windows Event Log)
- RunDLL Loading DLL By Ordinal
- Rundll32 Command Line (PowerShell)
- Rundll32 Command Line (Sysmon)
- Rundll32 Command Line (Windows Event Log)
- Rundll32 Control RunDLL Hunt
- Rundll32 Control RunDLL World Writable Directory
- Rundll32 DNSQuery
- Rundll32 LockWorkStation
- Rundll32 Process Creating Exe Dll Files
- Rundll32 Suspicious Command Line (PowerShell)
- Rundll32 Suspicious Command Line (Sysmon)
- Rundll32 Suspicious Command Line (Windows Event Log)
- rundll32 Suspicious Parent Process (Sysmon)
- rundll32 Suspicious Parent Process (Windows Event Log)
- Rundll32 with no Command Line Arguments with Network
- rundll32 with No DLL in Command Line (Sysmon)
- rundll32 with No DLL in Command Line (Windows Event Log)
- Rundll32.exe as Parent Process (Sysmon)
- Rundll32.exe as Parent Process (Windows Event Log)
- rundll32.exe Executing DLL from Non-standard Directory (PowerShell)
- rundll32.exe Executing DLL from Non-standard Directory (Sysmon)
- rundll32.exe Executing DLL from Non-standard Directory (Windows Event Log)
- Shell Spawned by Web Server - Windows (Windows Event Log)
- Suspicious Child Process for hh.exe (Sysmon)
- Suspicious Child Process for hh.exe (Windows Event Log)
- Suspicious Child Process for mshta.exe (Sysmon)
- Suspicious Child Process for mshta.exe (Windows Event Log)
- Suspicious Execution via Microsoft Common Console (Sysmon)
- Suspicious Execution via Microsoft Common Console (Windows Event Log)
- Suspicious IcedID Rundll32 Cmdline
- Suspicious mshta child process
- Suspicious mshta spawn
- Suspicious Parent Process for msiexec.exe (Sysmon)
- Suspicious Parent Process for msiexec.exe (Windows Event Log)
- Suspicious reCAPTCHA Command Line (PowerShell)
- Suspicious reCAPTCHA Command Line (Sysmon)
- Suspicious Regsvr32 Register Suspicious Path
- Suspicious Rundll32 dllregisterserver
- Suspicious Rundll32 no Command Line Arguments
- Suspicious Rundll32 PluginInit
- Suspicious Rundll32 StartW
- SyncAppvPublishingServer Execution (Windows Event Log)
- UAC Bypass MMC Load Unsigned Dll
- UAC Bypass With Colorui COM Object
- Uninstall App Using MsiExec
- Verclsid CLSID Execution
- Wbemprox COM Object Execution
- Windows Advanced Installer MSIX with AI_STUBS Execution
- Windows Application Whitelisting Bypass Attempt via Rundll32
- Windows AppLocker Block Events
- Windows AppLocker Execution from Uncommon Locations
- Windows AppLocker Privilege Escalation via Unauthorized Bypass
- Windows AppLocker Rare Application Launch Detection
- Windows Binary Proxy Execution Mavinject DLL Injection
- Windows BitLockerToGo Process Execution
- Windows BitLockerToGo with Network Activity
- Windows Diskshadow Proxy Execution
- Windows DotNet Binary in Non Standard Path
- Windows Execute Arbitrary Commands with MSDT
- Windows Execution of Microsoft MSC File In Suspicious Path
- Windows GrimResource - MMC Process Accessing APDS DLL
- Windows HTTP Network Communication From MSIExec
- Windows InstallUtil Credential Theft
- Windows InstallUtil in Non Standard Path
- Windows InstallUtil Remote Network Connection
- Windows InstallUtil Uninstall Option
- Windows InstallUtil URL in Command Line
- Windows IOBit Unlocker Extension DLL Registration via Regsvr32
- Windows LOLBAS Executed As Renamed File
- Windows LOLBAS Executed Outside Expected Path
- Windows Mock Trusted Directory MSC File Creation
- Windows MSC EvilTwin Directory Path Manipulation
- Windows Mshta Execution In Registry
- Windows MSHTA Writing to World Writable Path
- Windows MSI Rollback Script Deleted By Non-Msiexec Process
- Windows MSIExec DLLRegisterServer
- Windows MsiExec HideWindow Rundll32 Execution
- Windows MSIExec Remote Download
- Windows MSIExec Spawn Discovery Command
- Windows MSIExec Spawn WinDBG
- Windows MSIExec Unregister DLLRegisterServer
- Windows Odbcconf Hunting
- Windows Odbcconf Load DLL
- Windows Odbcconf Load Response File
- Windows Process Writing File to World Writable Path
- Windows Proxy Execution of .NET Utilities via Scripts
- Windows Rasautou DLL Execution
- Windows Regsvr32 Renamed Binary
- Windows Rundll32 Apply User Settings Changes
- Windows Rundll32 Load DLL in Temp Dir
- Windows Rundll32 with Non-Standard File Extension
- Windows System Binary Proxy Execution Compiled HTML File Decompile
- Windows System Script Proxy Execution Syncappvpublishingserver
- Windows Unusual Process Load Mozilla NSS-Mozglue Module
- wuauclt.exe Network Connection (Sysmon)
- wuauclt.exe Network Connection (Windows Event Log)
Kusto 8 rules
- CertUtil Used for File Download (Living off the Land)
- Detect Msiexec executing DLL network connections
- Process Injection Initiated By MMC
- Regsvr32 Rundll32 Image Loads Abnormal Extension
- Regsvr32 Rundll32 with Anomalous Parent Process
- Script Interpreter Loading DotNet Assembly From Memory
- Suspicious MSC File Launched
- Suspicious use of CPL file