Technique with 14 sub-techniques.View on attack.mitre.org
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Several Microsoft signed binaries that are default on Windows installations can be used to proxy execution of other files or commands.
Similarly, on Linux systems adversaries may abuse trusted binaries such as split to proxy execution of malicious commands.
Rules on DetectionCode tagged with T1218 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI | Anomaly | NULL | Cisco Network Visibility Module Flow Data | T1218.005 |
| Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download | Anomaly | NULL | Cisco Network Visibility Module Flow Data | T1218.005 |
| Cisco NVM - Suspicious Network Connection From Process With No Args | Anomaly | NULL | Cisco Network Visibility Module Flow Data | T1218 |
| CMLUA Or CMSTPLUA UAC Bypass | TTP | NULL | Sysmon EventID 7 | T1218.003 |
| Control Loading from World Writable Directory | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.002 |
| Detect HTML Help Renamed | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.001 |
| Detect HTML Help Spawn Child Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.001 |
| Detect HTML Help URL in Command Line | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data | T1218.001 |
| Detect HTML Help Using InfoTech Storage Handlers | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.001 |
| Detect mshta inline hta execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.005 |
| Detect mshta renamed | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.005 |
| Detect MSHTA Url in Command Line | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data | T1218.005 |
| Detect Regasm Spawning a Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.009 |
| Detect Regasm with Network Connection | TTP | NULL | Sysmon EventID 3 | T1218.009 |
| Detect Regasm with no Command Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.009 |
| Detect Regsvcs Spawning a Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.009 |
| Detect Regsvcs with Network Connection | TTP | NULL | Sysmon EventID 3 | T1218.009 |
| Detect Regsvcs with No Command Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.009 |
| Detect Regsvr32 Application Control Bypass | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.010 |
| Detect Rundll32 Application Control Bypass - advpack | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.011 |
| Detect Rundll32 Application Control Bypass - setupapi | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.011 |
| Detect Rundll32 Application Control Bypass - syssetup | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.011 |
| Detect Rundll32 Inline HTA Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.005 |
| LOLBAS Network Connection On Uncommon Port | Anomaly | NULL | Sysmon EventID 3 | T1218 |
| LOLBAS Rare Network Connection | Anomaly | NULL | Sysmon EventID 3 | T1218 |
| LOLBAS With Network Traffic | TTP | NULL | Sysmon EventID 3 | T1218 |
| Malicious InProcServer32 Modification | TTP | NULL | Sysmon EventID 12, Sysmon EventID 13 | T1218.010 |
| Mmc LOLBAS Execution Process Spawn | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.014 |
| Mshta spawning Rundll32 OR Regsvr32 Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.005 |
| Possible Lateral Movement PowerShell Spawn | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 | T1218.014 |
| Regsvr32 Silent and Install Param Dll Loading | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.010 |
| Regsvr32 with Known Silent Switch Cmdline | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.010 |
| RunDLL Loading DLL By Ordinal | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.011 |
| Rundll32 Control RunDLL Hunt | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.011 |
| Rundll32 Control RunDLL World Writable Directory | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.011 |
| Rundll32 DNSQuery | TTP | NULL | Sysmon EventID 22 | T1218.011 |
| Rundll32 LockWorkStation | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.011 |
| Rundll32 Process Creating Exe Dll Files | TTP | NULL | Sysmon EventID 11 | T1218.011 |
| Rundll32 with no Command Line Arguments with Network | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 3 | T1218.011 |
| Suspicious IcedID Rundll32 Cmdline | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.011 |
| Suspicious mshta child process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.005 |
| Suspicious mshta spawn | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.005 |
| Suspicious Regsvr32 Register Suspicious Path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.010 |
| Suspicious Rundll32 dllregisterserver | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.011 |
| Suspicious Rundll32 no Command Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.011 |
| Suspicious Rundll32 PluginInit | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.011 |
| Suspicious Rundll32 Rename | Hunting | NULL | Sysmon EventID 1 | T1218.011 |
| Suspicious Rundll32 StartW | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.011 |
| UAC Bypass MMC Load Unsigned Dll | TTP | NULL | Sysmon EventID 7 | T1218.014 |
| UAC Bypass With Colorui COM Object | TTP | NULL | Sysmon EventID 7 | T1218.003 |
| Uninstall App Using MsiExec | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.007 |
| Verclsid CLSID Execution | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.012 |
| Wbemprox COM Object Execution | TTP | NULL | Sysmon EventID 7 | T1218.003 |
| Windows Advanced Installer MSIX with AI_STUBS Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218 |
| Windows Application Whitelisting Bypass Attempt via Rundll32 | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.011 |
| Windows AppLocker Block Events | Anomaly | NULL | T1218 | |
| Windows AppLocker Execution from Uncommon Locations | Hunting | NULL | T1218 | |
| Windows AppLocker Privilege Escalation via Unauthorized Bypass | TTP | NULL | T1218 | |
| Windows AppLocker Rare Application Launch Detection | Hunting | NULL | T1218 | |
| Windows Binary Proxy Execution Mavinject DLL Injection | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.013 |
| Windows BitLockerToGo Process Execution | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688 | T1218 |
| Windows BitLockerToGo with Network Activity | Hunting | NULL | Sysmon EventID 22 | T1218 |
| Windows Diskshadow Proxy Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218 |
| Windows DotNet Binary in Non Standard Path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.004 |
| Windows Execute Arbitrary Commands with MSDT | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218 |
| Windows Execution of Microsoft MSC File In Suspicious Path | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.014 |
| Windows GrimResource - MMC Process Accessing APDS DLL | TTP | NULL | Windows Event Log Security 4663 | T1218.014 |
| Windows HTTP Network Communication From MSIExec | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 3, Cisco Network Visibility Module Flow Data | T1218.007 |
| Windows InstallUtil Credential Theft | TTP | NULL | Sysmon EventID 7 | T1218.004 |
| Windows InstallUtil in Non Standard Path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.004 |
| Windows InstallUtil Remote Network Connection | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 3, Cisco Network Visibility Module Flow Data | T1218.004 |
| Windows InstallUtil Uninstall Option | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.004 |
| Windows InstallUtil Uninstall Option with Network | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 3 | T1218.004 |
| Windows InstallUtil URL in Command Line | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data | T1218.004 |
| Windows IOBit Unlocker Extension DLL Registration via Regsvr32 | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.010 |
| Windows LOLBAS Executed As Renamed File | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.011 |
| Windows LOLBAS Executed Outside Expected Path | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688 | T1218.011 |
| Windows Mock Trusted Directory MSC File Creation | TTP | NULL | Sysmon EventID 11 | T1218.014 |
| Windows MSC EvilTwin Directory Path Manipulation | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218 |
| Windows Mshta Execution In Registry | TTP | NULL | Sysmon EventID 13 | T1218.005 |
| Windows MSHTA Writing to World Writable Path | TTP | NULL | Sysmon EventID 11 | T1218.005 |
| Windows MSI Rollback Script Deleted By Non-Msiexec Process | TTP | NULL | Sysmon EventID 23, Sysmon EventID 26 | T1218.007 |
| Windows MSIExec DLLRegisterServer | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.007 |
| Windows MsiExec HideWindow Rundll32 Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.007 |
| Windows MSIExec Remote Download | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data | T1218.007 |
| Windows MSIExec Spawn Discovery Command | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.007 |
| Windows MSIExec Spawn WinDBG | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.007 |
| Windows MSIExec Unregister DLLRegisterServer | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.007 |
| Windows MSIExec With Network Connections | TTP | NULL | Sysmon EventID 1 AND Sysmon EventID 3 | T1218.007 |
| Windows Odbcconf Hunting | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.008 |
| Windows Odbcconf Load DLL | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.008 |
| Windows Odbcconf Load Response File | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.008 |
| Windows Process Writing File to World Writable Path | Hunting | NULL | Sysmon EventID 11 | T1218.005 |
| Windows Proxy Execution of .NET Utilities via Scripts | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218 |
| Windows Rasautou DLL Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218 |
| Windows Regsvr32 Renamed Binary | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.010 |
| Windows Rundll32 Apply User Settings Changes | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.011 |
| Windows Rundll32 Load DLL in Temp Dir | Anomaly | NULL | Sysmon EventID 1 | T1218.011 |
| Windows Rundll32 with Non-Standard File Extension | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.011 |
| Windows System Binary Proxy Execution Compiled HTML File Decompile | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218.001 |
| Windows System Script Proxy Execution Syncappvpublishingserver | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1218 |
| Windows Unusual Process Load Mozilla NSS-Mozglue Module | Anomaly | NULL | Sysmon EventID 7 | T1218.003 |
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| GroupLazarus Group | Lazarus Group lnk files used for persistence have abused the Windows Update Client ( |
| GroupVolt Typhoon | Volt Typhoon has used native tools and processes including living off the land binaries or “LOLBins" to maintain and expand access to the victim networks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.