MITRE ATT&CK technique
System Script Proxy Execution detection rulesT1216
System Script Proxy Execution (T1216) is a MITRE ATT&CK technique in the Stealth tactic. This page lists the 15 community-maintained Sigma detection rules in the library mapped to T1216 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows.
Potential Manage-bde.wsf Abuse To Proxy Execution
highDetects potential abuse of the "manage-bde.wsf" script as a LOLBIN to proxy execution
windows · process_creation
Suspicious CustomShellHost Execution
highDetects the execution of CustomShellHost.exe where the child isn't located in 'C:\Windows\explorer.exe'. CustomShellHost is a known LOLBin that can be abused by attackers for defense evasion techniques.
windows · process_creation
Assembly Loading Via CL_LoadAssembly.ps1
mediumDetects calls to "LoadAssemblyFromPath" or "LoadAssemblyFromNS" that are part of the "CL_LoadAssembly.ps1" script. This can be abused to load different assemblies and bypass App locker controls.
windows · process_creation
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl
mediumDetects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)
windows · process_creation
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File
mediumDetects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)
windows · file_event
Execute Code with Pester.bat
mediumDetects code execution via Pester.bat (Pester - Powershell Modulte for testing)
windows · process_creation
Execute Code with Pester.bat as Parent
mediumDetects code execution via Pester.bat (Pester - Powershell Modulte for testing)
windows · process_creation
Launch-VsDevShell.PS1 Proxy Execution
mediumDetects the use of the 'Launch-VsDevShell.ps1' Microsoft signed script to execute commands.
windows · process_creation
Potential Process Execution Proxy Via CL_Invocation.ps1
mediumDetects calls to "SyncInvoke" that is part of the "CL_Invocation.ps1" script to proxy execution using "System.Diagnostics.Process"
windows · process_creation
Potential Script Proxy Execution Via CL_Mutexverifiers.ps1
mediumDetects the use of the Microsoft signed script "CL_mutexverifiers" to proxy the execution of additional PowerShell script commands
windows · process_creation
Pubprn.vbs Proxy Execution
mediumDetects the use of the 'Pubprn.vbs' Microsoft signed script to execute commands.
windows · process_creation
Remote Code Execute via Winrm.vbs
mediumDetects an attempt to execute code or create service on remote host via winrm.vbs.
windows · process_creation
SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code
mediumExecutes arbitrary PowerShell code using SyncAppvPublishingServer.vbs
windows · process_creation
Uncommon Sigverif.EXE Child Process
mediumDetects uncommon child processes spawning from "sigverif.exe", which could indicate potential abuse of the latter as a living of the land binary in order to proxy execution.
windows · process_creation
UtilityFunctions.ps1 Proxy Dll
mediumDetects the use of a Microsoft signed script executing a managed DLL with PowerShell.
windows · process_creation