System Script Proxy Execution

T1216

Technique with 2 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may use trusted scripts, often signed with certificates, to proxy the execution of malicious files. Several Microsoft signed scripts that have been downloaded from Microsoft or are default on Windows installations can be used to proxy execution of other files. This behavior may be abused by adversaries to execute malicious files that could bypass application control and signature validation on systems.

Detection rules16

Rules on DetectionCode tagged with T1216 or one of its sub-techniques.

Sigma15

RuleLevelLog sourceTechnique
Potential Manage-bde.wsf Abuse To Proxy Executionhighwindows / process_creationT1216
Suspicious CustomShellHost Executionhighwindows / process_creationT1216
Assembly Loading Via CL_LoadAssembly.ps1mediumwindows / process_creationT1216
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xslmediumwindows / process_creationT1216
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - Filemediumwindows / file_eventT1216
Execute Code with Pester.batmediumwindows / process_creationT1216
Execute Code with Pester.bat as Parentmediumwindows / process_creationT1216
Launch-VsDevShell.PS1 Proxy Executionmediumwindows / process_creationT1216.001
Potential Process Execution Proxy Via CL_Invocation.ps1mediumwindows / process_creationT1216
Potential Script Proxy Execution Via CL_Mutexverifiers.ps1mediumwindows / process_creationT1216
Pubprn.vbs Proxy Executionmediumwindows / process_creationT1216.001
Remote Code Execute via Winrm.vbsmediumwindows / process_creationT1216
SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Codemediumwindows / process_creationT1216
Uncommon Sigverif.EXE Child Processmediumwindows / process_creationT1216
UtilityFunctions.ps1 Proxy Dllmediumwindows / process_creationT1216

Splunk1

RuleTypeRiskData sourceTechnique
Windows System Script Proxy Execution SyncappvpublishingserverTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1216

Sub-techniques2

IDNameExamples
T1216.001PubPrn1
T1216.002SyncAppvPublishingServer0

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples0

No procedure examples are recorded for this technique.

References2

  1. GitHub Ultimate AppLocker Bypass List Open source
    Moe, O. (2018, March 1). Ultimate AppLocker Bypass List. Retrieved April 10, 2018.
  2. LOLBAS Project Open source
    Oddvar Moe et al. (2022, February). Living Off The Land Binaries, Scripts and Libraries. Retrieved March 7, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.