// MITRE ATT&CK
T1218 · System Binary Proxy Execution
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already nati...
¿Cómo detectarlo y mitigarlo?
La detección de System Binary Proxy Execution parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Sub-técnicas (14)
T1218.001
Compiled HTML File T1218.002
Control Panel T1218.003
CMSTP T1218.004
InstallUtil T1218.005
Mshta T1218.007
Msiexec T1218.008
Odbcconf T1218.009
Regsvcs/Regasm T1218.010
Regsvr32 T1218.011
Rundll32 T1218.012
Verclsid T1218.013
Mavinject T1218.014
MMC T1218.015
Electron Applications
Compiled HTML File T1218.002
Control Panel T1218.003
CMSTP T1218.004
InstallUtil T1218.005
Mshta T1218.007
Msiexec T1218.008
Odbcconf T1218.009
Regsvcs/Regasm T1218.010
Regsvr32 T1218.011
Rundll32 T1218.012
Verclsid T1218.013
Mavinject T1218.014
MMC T1218.015
Electron Applications
Técnicas relacionadas
T1055.011
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.