// MITRE ATT&CK
T1218 · System Binary Proxy Execution
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already nati...
How to detect & mitigate it
Detecting System Binary Proxy Execution starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (14)
T1218.001
Compiled HTML File T1218.002
Control Panel T1218.003
CMSTP T1218.004
InstallUtil T1218.005
Mshta T1218.007
Msiexec T1218.008
Odbcconf T1218.009
Regsvcs/Regasm T1218.010
Regsvr32 T1218.011
Rundll32 T1218.012
Verclsid T1218.013
Mavinject T1218.014
MMC T1218.015
Electron Applications
Compiled HTML File T1218.002
Control Panel T1218.003
CMSTP T1218.004
InstallUtil T1218.005
Mshta T1218.007
Msiexec T1218.008
Odbcconf T1218.009
Regsvcs/Regasm T1218.010
Regsvr32 T1218.011
Rundll32 T1218.012
Verclsid T1218.013
Mavinject T1218.014
MMC T1218.015
Electron Applications
Related techniques
T1055.011
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.