Trusted Developer Utilities Proxy Execution

T1127

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may take advantage of trusted developer utilities to proxy execution of malicious payloads. There are many utilities used for software development related tasks that can be used to execute code in various forms to assist in development, debugging, and reverse engineering. These utilities may often be signed with legitimate certificates that allow them to execute on a system and proxy execution of malicious code through a trusted process that effectively bypasses application control solutions.

Smart App Control is a feature of Windows that blocks applications it considers potentially malicious from running by verifying unsigned applications against a known safe list from a Microsoft cloud service before executing them. However, adversaries may leverage "reputation hijacking" to abuse an operating system’s trust of safe, signed applications that support the execution of arbitrary code. By leveraging Trusted Developer Utilities Proxy Execution to run their malicious code, adversaries may bypass Smart App Control protections.

Detection rules27

Rules on DetectionCode tagged with T1127 or one of its sub-techniques.

Sigma20

RuleLevelLog sourceTechnique
Kavremover Dropped Binary LOLBIN Usagehighwindows / process_creationT1127
Potential Arbitrary Code Execution Via Node.EXEhighwindows / process_creationT1127
Potentially Suspicious ASP.NET Compilation Via AspNetCompilerhighwindows / process_creationT1127
Remote Thread Creation Ttdinject.exe Proxyhighwindows / create_remote_threadT1127
Silenttrinity Stager Msbuild Activityhighwindows / network_connectionT1127.001
Suspicious Child Process of AspNetCompilerhighwindows / process_creationT1127
Suspicious File Created by ArcSOC.exehighwindows / file_eventT1127
Suspicious Use of CSharp Interactive Consolehighwindows / process_creationT1127
AspNetCompiler Executionmediumwindows / process_creationT1127
C# IL Code Compilation Via Ilasm.EXEmediumwindows / process_creationT1127
Detection of PowerShell Execution via Sqlps.exemediumwindows / process_creationT1127
Node Process Executionsmediumwindows / process_creationT1127
Potential Binary Proxy Execution Via Cdb.EXEmediumwindows / process_creationT1127
Potential Mftrace.EXE Abusemediumwindows / process_creationT1127
SQL Client Tools PowerShell Session Detectionmediumwindows / process_creationT1127

Splunk7

RuleTypeRiskData sourceTechnique
ETW Registry DisabledTTPNULLSysmon EventID 13T1127
MSBuild Suspicious Spawned By Script ProcessTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1127.001
Suspicious microsoft workflow compiler renameHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1127
Suspicious microsoft workflow compiler usageTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1127
Suspicious msbuild pathTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1127.001
Suspicious MSBuild RenameHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1127.001
Suspicious MSBuild SpawnTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1127.001

Sub-techniques3

IDNameExamples
T1127.001MSBuild5
T1127.002ClickOnce0
T1127.003JamPlus0

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples0

No procedure examples are recorded for this technique.

References6

  1. Elastic Security Labs Open source
    Joe Desimone. (2024, August 5). Dismantling Smart App Control. Retrieved March 21, 2025.
  2. Exploit Monday WinDbg Open source
    Graeber, M. (2016, August 15). Bypassing Application Whitelisting by using WinDbg/CDB as a Shellcode Runner. Retrieved November 17, 2024.
  3. LOLBAS Tracker Open source
    LOLBAS. (n.d.). Tracker.exe. Retrieved July 31, 2019.
  4. Microsoft Smart App Control Open source
    Microsoft. (n.d.). Smart App Control Frequently Asked Questions. Retrieved April 4, 2025.
  5. engima0x3 DNX Bypass Open source
    Nelson, M. (2017, November 17). Bypassing Application Whitelisting By Using dnx.exe. Retrieved May 25, 2017.
  6. engima0x3 RCSI Bypass Open source
    Nelson, M. (2016, November 21). Bypassing Application Whitelisting By Using rcsi.exe. Retrieved May 26, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.