MITRE ATT&CK technique
System Binary Proxy Execution detection rulesT1218
System Binary Proxy Execution (T1218) is a MITRE ATT&CK technique in the Stealth tactic. This page lists the 255 community-maintained Sigma detection rules in the library mapped to T1218 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, macos.
Top products
Tactic
APT29 2018 Phishing Campaign CommandLine Indicators
criticalDetects indicators of APT 29 (Cozy Bear) phishing-campaign as reported by mandiant
windows · process_creation
APT29 2018 Phishing Campaign File Indicators
criticalDetects indicators of APT 29 (Cozy Bear) phishing-campaign as reported by mandiant
windows · file_event
Equation Group DLL_U Export Function Load
criticalDetects a specific export function name used by one of EquationGroup tools
windows · process_creation
EvilNum APT Golden Chickens Deployment Via OCX Files
criticalDetects Golden Chickens deployment method as used by Evilnum and described in ESET July 2020 report
windows · process_creation
HackTool - F-Secure C3 Load by Rundll32
criticalF-Secure C3 produces DLLs with a default exported StartNodeRelay function.
windows · process_creation
NotPetya Ransomware Activity
criticalDetects NotPetya ransomware activity in which the extracted passwords are passed back to the main module via named pipe, the file system journal of drive C is deleted and Windows eventlogs are cleared using wevtutil
windows · process_creation
Potential Emotet Rundll32 Execution
criticalDetecting Emotet DLL loading by looking for rundll32.exe processes with command lines ending in ,RunDLL or ,Control_RunDLL
windows · process_creation
ZxShell Malware
criticalDetects a ZxShell start by the called and well-known function name
windows · process_creation
Arbitrary File Download Via IMEWDBLD.EXE
highDetects usage of "IMEWDBLD.exe" to download arbitrary files
windows · process_creation
BaaUpdate.exe Suspicious DLL Load
highDetects BitLocker Access Agent Update Utility (baaupdate.exe) loading DLLs from suspicious locations that are publicly writable which could indicate an attempt to lateral movement via BitLocker DCOM & COM Hijacking. This technique abuses COM Classes configured as INTERACTIVE USER to spawn processes in the context of the logged-on user's session. Specifically, it targets the BDEUILauncher Class (CLSID ab93b6f1-be76-4185-a488-a9001b105b94) which can launch BaaUpdate.exe, which is vulnerable to COM Hijacking when started with input parameters. This allows attackers to execute code in the user's context without needing to steal credentials or use additional techniques to compromise the account.
windows · image_load
Bad Opsec Defaults Sacrificial Processes With Improper Arguments
highDetects attackers using tooling with bad opsec defaults. E.g. spawning a sacrificial process to inject a capability into the process without taking into account how the process is normally run. One trivial example of this is using rundll32.exe without arguments as a sacrificial process (default in CS, now highlighted by c2lint), running WerFault without arguments (Kraken - credit am0nsec), and other examples.
windows · process_creation
Bypass UAC via CMSTP
highDetect commandline usage of Microsoft Connection Manager Profile Installer (cmstp.exe) to install specially formatted local .INF files
windows · process_creation
CMSTP Execution Process Access
highDetects various indicators of Microsoft Connection Manager Profile Installer execution
windows · process_access
CMSTP Execution Process Creation
highDetects various indicators of Microsoft Connection Manager Profile Installer execution
windows · process_creation
CMSTP Execution Registry Event
highDetects various indicators of Microsoft Connection Manager Profile Installer execution
windows · registry_event
CMSTP UAC Bypass via COM Object Access
highDetects UAC Bypass Attempt Using Microsoft Connection Manager Profile Installer Autoelevate-capable COM Objects (e.g. UACMe ID of 41, 43, 58 or 65)
windows · process_creation
CobaltStrike Load by Rundll32
highRundll32 can be use by Cobalt Strike with StartW function to load DLLs from the command line.
windows · process_creation
Control Panel Items
highDetects the malicious use of a control panel item
windows · process_creation
Csc.EXE Execution Form Potentially Suspicious Parent
highDetects a potentially suspicious parent of "csc.exe", which could be a sign of payload delivery.
windows · process_creation
Curl Download And Execute Combination
highAdversaries can use curl to download payloads remotely and execute them. Curl is included by default in Windows 10 build 17063 and later.
windows · process_creation
Devtoolslauncher.exe Executes Specified Binary
highThe Devtoolslauncher.exe executes other binary
windows · process_creation
DLL Loaded From Suspicious Location Via Cmspt.EXE
highDetects cmstp loading "dll" or "ocx" files from suspicious locations
windows · image_load
Execute Pcwrun.EXE To Leverage Follina
highDetects indirect command execution via Program Compatibility Assistant "pcwrun.exe" leveraging the follina (CVE-2022-30190) vulnerability
windows · process_creation
Execution DLL of Choice Using WAB.EXE
highThis rule detects that the path to the DLL written in the registry is different from the default one. Launched WAB.exe tries to load the DLL from Registry.
windows · registry_set
Execution via stordiag.exe
highDetects the use of stordiag.exe to execute schtasks.exe systeminfo.exe and fltmc.exe
windows · process_creation
Execution via WorkFolders.exe
highDetects using WorkFolders.exe to execute an arbitrary control.exe
windows · process_creation
File Download Via Windows Defender MpCmpRun.EXE
highDetects the use of Windows Defender MpCmdRun.EXE to download files
windows · process_creation
Fireball Archer Install
highDetects Archer malware invocation via rundll32
windows · process_creation
HackTool - CACTUSTORCH Remote Thread Creation
highDetects remote thread creation from CACTUSTORCH as described in references.
windows · create_remote_thread
HackTool - RedMimicry Winnti Playbook Execution
highDetects actions caused by the RedMimicry Winnti playbook a automated breach emulations utility
windows · process_creation
HTML Help HH.EXE Suspicious Child Process
highDetects a suspicious child process of a Microsoft HTML Help (HH.exe)
windows · process_creation
IcedID Malware Suspicious Single Digit DLL Execution Via Rundll32
highDetects RunDLL32.exe executing a single digit DLL named "1.dll" with the export function "DllRegisterServer". This behaviour was often seen used by malware and especially IcedID
windows · process_creation
Kapeka Backdoor Execution Via RunDLL32.EXE
highDetects Kapeka backdoor process execution pattern, where the dropper launch the backdoor binary by calling rundll32 and passing the backdoor's first export ordinal (#1) with a "-d" argument.
windows · process_creation
Kapeka Backdoor Loaded Via Rundll32.EXE
highDetects the Kapeka Backdoor binary being loaded by rundll32.exe. The Kapeka loader drops a backdoor, which is a DLL with the '.wll' extension masquerading as a Microsoft Word Add-In.
windows · image_load
Legitimate Application Dropped Archive
highDetects programs on a Windows system that should not write an archive to disk
windows · file_event
Legitimate Application Dropped Executable
highDetects LOLBINs and applications that should not legitimately drop executable or executable-equivalent files to disk. This may indicate malware staging, process injection, or abuse of a trusted binary for payload delivery.
windows · file_event
Legitimate Application Dropped Script
highDetects LOLBINs and applications that should not legitimately drop script files to disk. This may indicate malware staging or abuse of a trusted binary for script-based code execution.
windows · file_event
Legitimate Application Writing Files In Uncommon Location
highDetects legitimate applications writing any type of file to uncommon or suspicious locations that are not typical for application data storage or execution. Adversaries may leverage legitimate applications (Living off the Land Binaries - LOLBins) to drop or download malicious files to uncommon locations on the system to evade detection by security solutions.
windows · file_event
Mavinject Inject DLL Into Running Process
highDetects process injection using the signed Windows tool "Mavinject" via the "INJECTRUNNING" flag
windows · process_creation
MMC Executing Files with Reversed Extensions Using RTLO Abuse
highDetects malicious behavior where the MMC utility (`mmc.exe`) executes files with reversed extensions caused by Right-to-Left Override (RLO) abuse, disguising them as document formats.
windows · process_creation
MpiExec Lolbin
highDetects a certain command line flag combination used by mpiexec.exe LOLBIN from HPC pack that can be used to execute any other binary
windows · process_creation
MSDT Execution Via Answer File
highDetects execution of "msdt.exe" using an answer file which is simulating the legitimate way of calling msdt via "pcwrun.exe" (For example from the compatibility tab).
windows · process_creation
MSHTA Execution with Suspicious File Extensions
highDetects execution of mshta.exe with file types that looks like they do not typically represent HTA (HTML Application) content, such as .png, .jpg, .zip, .pdf, and others, which are often polyglots. MSHTA is a legitimate Windows utility for executing HTML Applications containing VBScript or JScript. Threat actors often abuse this lolbin utility to download and execute malicious scripts disguised as benign files or hosted under misleading extensions to evade detection.
windows · process_creation
Network Connection Initiated By AddinUtil.EXE
highDetects a network connection initiated by the Add-In deployment cache updating utility "AddInutil.exe". This could indicate a potential command and control communication as this tool doesn't usually initiate network activity.
windows · network_connection
Obfuscated PowerShell MSI Install via WindowsInstaller COM
highDetects the execution of obfuscated PowerShell commands that attempt to install MSI packages via the Windows Installer COM object (`WindowsInstaller.Installer`). The technique involves manipulating strings to hide functionality, such as constructing class names using string insertion (e.g., 'indowsInstaller.Installer'.Insert(0,'W')) and correcting malformed URLs (e.g., converting 'htps://' to 'https://') at runtime. This behavior is commonly associated with malware loaders or droppers that aim to bypass static detection by hiding intent in runtime-generated strings and using legitimate tools for code execution. The use of `InstallProduct` and COM object creation, particularly combined with hidden window execution and suppressed UI, indicates an attempt to install software (likely malicious) without user interaction.
windows · process_creation
Odbcconf.EXE Suspicious DLL Location
highDetects execution of "odbcconf" where the path of the DLL being registered is located in a potentially suspicious location.
windows · process_creation
OneNote.EXE Execution of Malicious Embedded Scripts
highDetects the execution of malicious OneNote documents that contain embedded scripts. When a user clicks on a OneNote attachment and then on the malicious link inside the ".one" file, it exports and executes the malicious embedded script from specific directories.
windows · process_creation
OpenWith.exe Executes Specified Binary
highThe OpenWith.exe executes other binary
windows · process_creation
Outbound Network Connection Initiated By Cmstp.EXE
highDetects a network connection initiated by Cmstp.EXE Its uncommon for "cmstp.exe" to initiate an outbound network connection. Investigate the source of such requests to determine if they are malicious.
windows · network_connection
Potential Baby Shark Malware Activity
highDetects activity that could be related to Baby Shark malware
windows · process_creation
Potential Bumblebee Remote Thread Creation
highDetects remote thread injection events based on action seen used by bumblebee
windows · create_remote_thread
Potential Compromised 3CXDesktopApp Execution
highDetects execution of known compromised version of 3CXDesktopApp
windows · process_creation
Potential Compromised 3CXDesktopApp Update Activity
highDetects the 3CXDesktopApp updater downloading a known compromised version of the 3CXDesktopApp software
windows · process_creation
Potential Devil Bait Malware Reconnaissance
highDetects specific process behavior observed with Devil Bait samples
windows · process_creation
Potential EmpireMonkey Activity
highDetects potential EmpireMonkey APT activity
windows · process_creation
Potential Exploitation of RCE Vulnerability CVE-2025-33053
highDetects potential exploitation of remote code execution vulnerability CVE-2025-33053 which involves unauthorized code execution via WebDAV through external control of file names or paths. The exploit abuses legitimate utilities like iediagcmd.exe or CustomShellHost.exe by manipulating their working directories to point to attacker-controlled WebDAV servers, causing them to execute malicious executables (like route.exe) from the WebDAV path instead of legitimate system binaries through Process.Start() search order manipulation.
windows · process_creation
Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Image Load
highDetects potential exploitation of remote code execution vulnerability CVE-2025-33053 by monitoring suspicious image loads from WebDAV paths. The exploit involves malicious executables from attacker-controlled WebDAV servers loading the Windows system DLLs like gdi32.dll, netapi32.dll, etc.
windows · image_load
Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Process Access
highDetects potential exploitation of remote code execution vulnerability CVE-2025-33053 by looking for process access that involves legitimate Windows executables (iediagcmd.exe, CustomShellHost.exe) accessing suspicious executables hosted on WebDAV shares. This indicates an attacker may be exploiting Process.Start() search order manipulation to execute malicious code from attacker-controlled WebDAV servers instead of legitimate system binaries. The vulnerability allows unauthorized code execution through external control of file names or paths via WebDAV.
windows · process_access
Potential LethalHTA Technique Execution
highDetects potential LethalHTA technique where the "mshta.exe" is spawned by an "svchost.exe" process
windows · process_creation
Potential NTLM Coercion Via Certutil.EXE
highDetects possible NTLM coercion via certutil using the 'syncwithWU' flag
windows · process_creation
Potential PowerShell Execution Via DLL
highDetects potential PowerShell execution from a DLL instead of the usual PowerShell process as seen used in PowerShdll. This detection assumes that PowerShell commands are passed via the CommandLine.
windows · process_creation
Potential Provisioning Registry Key Abuse For Binary Proxy Execution
highDetects potential abuse of the provisioning registry key for indirect command execution through "Provlaunch.exe".
windows · process_creation
Potential Provisioning Registry Key Abuse For Binary Proxy Execution - REG
highDetects potential abuse of the provisioning registry key for indirect command execution through "Provlaunch.exe".
windows · registry_set
Potential Raspberry Robin CPL Execution Activity
highDetects the execution of a ".CPL" file located in the user temp directory via the Shell32 DLL "Control_RunDLL" export function. This behavior was observed in multiple Raspberry-Robin variants.
windows · process_creation
Potential RemoteFXvGPUDisablement.EXE Abuse
highDetects PowerShell module creation where the module Contents are set to "function Get-VMRemoteFXPhysicalVideoAdapter". This could be a sign of potential abuse of the "RemoteFXvGPUDisablement.exe" binary which is known to be vulnerable to module load-order hijacking.
windows
Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell Module
highDetects PowerShell module creation where the module Contents are set to "function Get-VMRemoteFXPhysicalVideoAdapter". This could be a sign of potential abuse of the "RemoteFXvGPUDisablement.exe" binary which is known to be vulnerable to module load-order hijacking.
windows · ps_module
Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell ScriptBlock
highDetects PowerShell module creation where the module Contents are set to "function Get-VMRemoteFXPhysicalVideoAdapter". This could be a sign of potential abuse of the "RemoteFXvGPUDisablement.exe" binary which is known to be vulnerable to module load-order hijacking.
windows · ps_script
Potential Suspicious Child Process Of 3CXDesktopApp
highDetects potential suspicious child processes of "3CXDesktopApp.exe". Which could be related to the 3CXDesktopApp supply chain compromise
windows · process_creation
Potentially Suspicious Child Process Of Regsvr32
highDetects potentially suspicious child processes of "regsvr32.exe".
windows · process_creation
Potentially Suspicious Child Processes Spawned by ConHost
highDetects suspicious child processes related to Windows Shell utilities spawned by `conhost.exe`, which could indicate malicious activity using trusted system components.
windows · process_creation
Potentially Suspicious DLL Registered Via Odbcconf.EXE
highDetects execution of "odbcconf" with the "REGSVR" action where the DLL in question doesn't contain a ".dll" extension. Which is often used as a method to evade defenses.
windows · process_creation
Potentially Suspicious Mofcomp Execution
highDetects execution of the "mofcomp" utility as a child of a suspicious shell or script running utility or by having a suspicious path in the commandline. The "mofcomp" utility parses a file containing MOF statements and adds the classes and class instances defined in the file to the WMI repository. Attackers abuse this utility to install malicious MOF scripts
windows · process_creation
Potentially Suspicious Regsvr32 HTTP IP Pattern
highDetects regsvr32 execution to download and install DLLs located remotely where the address is an IP address.
windows · process_creation
Process Access via TrolleyExpress Exclusion
highDetects a possible process memory dump that uses the white-listed Citrix TrolleyExpress.exe filename as a way to dump the lsass process memory
windows · process_creation
Proxy Execution Via Wuauclt.EXE
highDetects the use of the Windows Update Client binary (wuauclt.exe) for proxy execution.
windows · process_creation
Regsvr32 DLL Execution With Suspicious File Extension
highDetects the execution of REGSVR32.exe with DLL files masquerading as other files
windows · process_creation
Regsvr32 Execution From Highly Suspicious Location
highDetects execution of regsvr32 where the DLL is located in a highly suspicious locations
windows · process_creation
Remote CHM File Download/Execution Via HH.EXE
highDetects the usage of "hh.exe" to execute/download remotely hosted ".chm" files.
windows · process_creation
RemoteFXvGPUDisablement Abuse Via AtomicTestHarnesses
highDetects calls to the AtomicTestHarnesses "Invoke-ATHRemoteFXvGPUDisablementCommand" which is designed to abuse the "RemoteFXvGPUDisablement.exe" binary to run custom PowerShell code via module load-order hijacking.
windows · process_creation
Remotely Hosted HTA File Executed Via Mshta.EXE
highDetects execution of the "mshta" utility with an argument containing the "http" keyword, which could indicate that an attacker is executing a remotely hosted malicious hta file
windows · process_creation
Renamed Mavinject.EXE Execution
highDetects the execution of a renamed version of the "Mavinject" process. Which can be abused to perform process injection using the "/INJECTRUNNING" flag
windows · process_creation
Renamed MegaSync Execution
highDetects the execution of a renamed MegaSync.exe as seen used by ransomware families like Nefilim, Sodinokibi, Pysa, and Conti.
windows · process_creation
Renamed ZOHO Dctask64 Execution
highDetects a renamed "dctask64.exe" execution, a signed binary by ZOHO Corporation part of ManageEngine Endpoint Central. This binary can be abused for DLL injection, arbitrary command and process execution.
windows · process_creation
RunDLL32 Spawning Explorer
highDetects RunDLL32.exe spawning explorer.exe as child, which is very uncommon, often observes Gamarue spawning the explorer.exe process in an unusual way
windows · process_creation
Rundll32 UNC Path Execution
highDetects rundll32 execution where the DLL is located on a remote location (share). Threat actors can abuse the rundll32.exe binary to execute remote DLLs from a UNC pathh.
windows · process_creation
Sdiagnhost Calling Suspicious Child Process
highDetects sdiagnhost.exe calling a suspicious child process (e.g. used in exploits for Follina / CVE-2022-30190)
windows · process_creation
Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location
highDetects the use of iexpress.exe to create binaries via Self Extraction Directive (SED) files located in potentially suspicious locations. This behavior has been observed in-the-wild by different threat actors.
windows · process_creation
Sensitive File Dump Via Print.EXE
highDetects the abuse of the Print.exe utility for credential harvesting which involves using Print.Exe to copy sensitive files such as ntds.dit, SAM, SECURITY, or SYSTEM from the Windows directory in order to extract credentials, locally or remotely.
windows · process_creation
Shell32 DLL Execution in Suspicious Directory
highDetects shell32.dll executing a DLL in a suspicious directory
windows · process_creation
Sofacy Trojan Loader Activity
highDetects Trojan loader activity as used by APT28
windows · process_creation
Suspicious AddinUtil.EXE CommandLine Execution
highDetects execution of the Add-In deployment cache updating utility (AddInutil.exe) with suspicious Addinroot or Pipelineroot paths. An adversary may execute AddinUtil.exe with uncommon Addinroot/Pipelineroot paths that point to the adversaries Addins.Store payload.
windows · process_creation
Suspicious AgentExecutor PowerShell Execution
highDetects execution of the AgentExecutor.exe binary. Which can be abused as a LOLBIN to execute powershell scripts with the ExecutionPolicy "Bypass" or any binary named "powershell.exe" located in the path provided by 6th positional argument
windows · process_creation
Suspicious BitLocker Access Agent Update Utility Execution
highDetects the execution of the BitLocker Access Agent Update Utility (baaupdate.exe) which is not a common parent process for other processes. Suspicious child processes spawned by baaupdate.exe could indicate an attempt at lateral movement via BitLocker DCOM & COM Hijacking.
windows · process_creation
Suspicious Child Process Of BgInfo.EXE
highDetects suspicious child processes of "BgInfo.exe" which could be a sign of potential abuse of the binary to proxy execution via external VBScript
windows · process_creation
Suspicious Control Panel DLL Load
highDetects suspicious Rundll32 execution from control.exe as used by Equation Group and Exploit Kits
windows · process_creation
Suspicious DLL Loaded via CertOC.EXE
highDetects when a user installs certificates by using CertOC.exe to load the target DLL file.
windows · process_creation
Suspicious DotNET CLR Usage Log Artifact
highDetects the creation of Usage Log files by the CLR (clr.dll). These files are named after the executing process once the assembly is finished executing for the first time in the (user) session context.
windows · file_event
Suspicious Driver/DLL Installation Via Odbcconf.EXE
highDetects execution of "odbcconf" with the "INSTALLDRIVER" action where the driver doesn't contain a ".dll" extension. This is often used as a defense evasion method.
windows · process_creation
Suspicious HH.EXE Execution
highDetects a suspicious execution of a Microsoft HTML Help (HH.exe)
windows · process_creation
Suspicious JavaScript Execution Via Mshta.EXE
highDetects execution of javascript code using "mshta.exe".
windows · process_creation
Suspicious Microsoft Office Child Process
highDetects a suspicious process spawning from one of the Microsoft Office suite products (Word, Excel, PowerPoint, Publisher, Visio, etc.)
windows · process_creation
Suspicious MSDT Parent Process
highDetects msdt.exe executed by a suspicious parent as seen in CVE-2022-30190 / Follina exploitation
windows · process_creation
Suspicious MSHTA Child Process
highDetects a suspicious process spawning from an "mshta.exe" process, which could be indicative of a malicious HTA script execution
windows · process_creation
Suspicious Provlaunch.EXE Child Process
highDetects suspicious child processes of "provlaunch.exe" which might indicate potential abuse to proxy execution.
windows · process_creation
Suspicious Regsvr32 Execution From Remote Share
highDetects REGSVR32.exe to execute DLL hosted on remote shares
windows · process_creation
Suspicious Response File Execution Via Odbcconf.EXE
highDetects execution of "odbcconf" with the "-f" flag in order to load a response file with a non-".rsp" extension.
windows · process_creation
Suspicious Rundll32 Activity Invoking Sys File
highDetects suspicious process related to rundll32 based on command line that includes a *.sys file as seen being used by UNC2452
windows · process_creation
Suspicious Rundll32 Execution With Image Extension
highDetects the execution of Rundll32.exe with DLL files masquerading as image files
windows · process_creation
Suspicious ShellExec_RunDLL Call Via Ordinal
highDetects suspicious call to the "ShellExec_RunDLL" exported function of SHELL32.DLL through the ordinal number to launch other commands. Adversary might only use the ordinal number in order to bypass existing detection that alert on usage of ShellExec_RunDLL on CommandLine.
windows · process_creation
Suspicious Speech Runtime Binary Child Process
highDetects suspicious Speech Runtime Binary Execution by monitoring its child processes. Child processes spawned by SpeechRuntime.exe could indicate an attempt for lateral movement via COM & DCOM hijacking.
windows · process_creation
Suspicious WMIC Execution Via Office Process
highOffice application called wmic to proxye execution through a LOLBIN process. This is often used to break suspicious parent-child chain (Office app spawns LOLBin).
windows · process_creation
Suspicious WmiPrvSE Child Process
highDetects suspicious and uncommon child processes of WmiPrvSE
windows · process_creation
Time Travel Debugging Utility Usage
highDetects usage of Time Travel Debugging Utility. Adversaries can execute malicious processes and dump processes, such as lsass.exe, via tttracer.exe.
windows · process_creation
Time Travel Debugging Utility Usage - Image
highDetects usage of Time Travel Debugging Utility. Adversaries can execute malicious processes and dump processes, such as lsass.exe, via tttracer.exe.
windows · image_load
Uncommon Child Process Of Setres.EXE
highDetects uncommon child process of Setres.EXE. Setres.EXE is a Windows server only process and tool that can be used to set the screen resolution. It can potentially be abused in order to launch any arbitrary file with a name containing the word "choice" from the current execution path.
windows · process_creation
Windows Shell/Scripting Processes Spawning Suspicious Programs
highDetects suspicious child processes of a Windows shell and scripting processes such as wscript, rundll32, powershell, mshta...etc.
windows · process_creation
Winrs Local Command Execution
highDetects the execution of Winrs.exe where it is used to execute commands locally. Commands executed this way are launched under Winrshost.exe and can represent proxy execution used for defense evasion or lateral movement.
windows · process_creation
Abusing Print Executable
mediumAttackers can use print.exe for remote file copy
windows · process_creation
AddinUtil.EXE Execution From Uncommon Directory
mediumDetects execution of the Add-In deployment cache updating utility (AddInutil.exe) from a non-standard directory.
windows · process_creation
AgentExecutor PowerShell Execution
mediumDetects execution of the AgentExecutor.exe binary. Which can be abused as a LOLBIN to execute powershell scripts with the ExecutionPolicy "Bypass" or any binary named "powershell.exe" located in the path provided by 6th positional argument
windows · process_creation
Arbitrary Command Execution Using WSL
mediumDetects potential abuse of Windows Subsystem for Linux (WSL) binary as a Living of the Land binary in order to execute arbitrary Linux or Windows commands.
windows · process_creation
Arbitrary DLL or Csproj Code Execution Via Dotnet.EXE
mediumDetects execution of arbitrary DLLs or unsigned code via a ".csproj" files via Dotnet.EXE.
windows · process_creation
Arbitrary File Download Via MSEDGE_PROXY.EXE
mediumDetects usage of "msedge_proxy.exe" to download arbitrary files
windows · process_creation
Arbitrary File Download Via MSOHTMED.EXE
mediumDetects usage of "MSOHTMED" to download arbitrary files
windows · process_creation
Arbitrary File Download Via MSPUB.EXE
mediumDetects usage of "MSPUB" (Microsoft Publisher) to download arbitrary files
windows · process_creation
Arbitrary File Download Via PresentationHost.EXE
mediumDetects usage of "PresentationHost" which is a utility that runs ".xbap" (Browser Applications) files to download arbitrary files
windows · process_creation
Arbitrary File Download Via Squirrel.EXE
mediumDetects the usage of the "Squirrel.exe" to download arbitrary files. This binary is part of multiple Electron based software installations (Slack, Teams, Discord, etc.)
windows · process_creation
Arbitrary MSI Download Via Devinit.EXE
mediumDetects a certain command line flag combination used by "devinit.exe", which can be abused as a LOLBIN to download arbitrary MSI packages on a Windows system
windows · process_creation
Atbroker Registry Change
mediumDetects creation/modification of Assistive Technology applications and persistence with usage of 'at'
windows · registry_event
Binary Proxy Execution Via Dotnet-Trace.EXE
mediumDetects commandline arguments for executing a child process via dotnet-trace.exe
windows · process_creation
Code Execution via Pcwutl.dll
mediumDetects launch of executable by calling the LaunchApplication function from pcwutl.dll library.
windows · process_creation
COM Object Execution via Xwizard.EXE
mediumDetects the execution of Xwizard tool with the "RunWizard" flag and a GUID like argument. This utility can be abused in order to run custom COM object created in the registry.
windows · process_creation
Created Files by Microsoft Sync Center
mediumThis rule detects suspicious files created by Microsoft Sync Center (mobsync)
windows · file_event
DeviceCredentialDeployment Execution
mediumDetects the execution of DeviceCredentialDeployment to hide a process from view.
windows · process_creation
Diskshadow Child Process Spawned
mediumDetects any child process spawning from "Diskshadow.exe". This could be due to executing Diskshadow in interpreter mode or script mode and using the "exec" flag to launch other applications.
windows · process_creation
Diskshadow Script Mode - Execution From Potential Suspicious Location
mediumDetects execution of "Diskshadow.exe" in script mode using the "/s" flag where the script is located in a potentially suspicious location.
windows · process_creation
Diskshadow Script Mode - Uncommon Script Extension Execution
mediumDetects execution of "Diskshadow.exe" in script mode to execute an script with a potentially uncommon extension. Initial baselining of the allowed extension list is required.
windows · process_creation
Diskshadow Script Mode Execution
mediumDetects execution of "Diskshadow.exe" in script mode using the "/s" flag. Attackers often abuse "diskshadow" to execute scripts that deleted the shadow copies on the systems. Investigate the content of the scripts and its location.
windows · process_creation
DLL Call by Ordinal Via Rundll32.EXE
mediumDetects calls of DLLs exports by ordinal numbers via rundll32.dll.
windows · process_creation
DLL Execution via Rasautou.exe
mediumDetects using Rasautou.exe for loading arbitrary .DLL specified in -d option and executes the export specified in -p.
windows · process_creation
DLL Loaded via CertOC.EXE
mediumDetects when a user installs certificates by using CertOC.exe to loads the target DLL file.
windows · process_creation
Dllhost.EXE Initiated Network Connection To Non-Local IP Address
mediumDetects Dllhost.EXE initiating a network connection to a non-local IP address. Aside from Microsoft own IP range that needs to be excluded. Network communication from Dllhost will depend entirely on the hosted DLL. An initial baseline is recommended before deployment.
windows · network_connection
DllUnregisterServer Function Call Via Msiexec.EXE
mediumDetects MsiExec loading a DLL and calling its DllUnregisterServer function
windows · process_creation
DNS Query Request By Regsvr32.EXE
mediumDetects DNS queries initiated by "Regsvr32.exe"
windows · dns_query
Driver/DLL Installation Via Odbcconf.EXE
mediumDetects execution of "odbcconf" with "INSTALLDRIVER" which installs a new ODBC driver. Attackers abuse this to install and run malicious DLLs.
windows · process_creation
Execute Files with Msdeploy.exe
mediumDetects file execution using the msdeploy.exe lolbin
windows · process_creation
File Download Using ProtocolHandler.exe
mediumDetects usage of "ProtocolHandler" to download files. Downloaded files will be located in the cache folder (for example - %LOCALAPPDATA%\Microsoft\Windows\INetCache\IE)
windows · process_creation
File Download Via InstallUtil.EXE
mediumDetects use of .NET InstallUtil.exe in order to download arbitrary files. The files will be written to "%LOCALAPPDATA%\Microsoft\Windows\INetCache\IE\"
windows · process_creation
Gpscript Execution
mediumDetects the execution of the LOLBIN gpscript, which executes logon or startup scripts configured in Group Policy
windows · process_creation
HH.EXE Initiated HTTP Network Connection
mediumDetects a network connection initiated by the "hh.exe" process to HTTP destination ports, which could indicate the execution/download of remotely hosted .chm files.
windows · network_connection
Hidden Flag Set On File/Directory Via Chflags - MacOS
mediumDetects the execution of the "chflags" utility with the "hidden" flag, in order to hide files on MacOS. When a file or directory has this hidden flag set, it becomes invisible to the default file listing commands and in graphical file browsers.
macos · process_creation
Ie4uinit Lolbin Use From Invalid Path
mediumDetect use of ie4uinit.exe to execute commands from a specially prepared ie4uinit.inf file from a directory other than the usual directories
windows · process_creation
Import LDAP Data Interchange Format File Via Ldifde.EXE
mediumDetects the execution of "Ldifde.exe" with the import flag "-i". The can be abused to include HTTP-based arguments which will allow the arbitrary download of files from a remote server.
windows · process_creation
InfDefaultInstall.exe .inf Execution
mediumExecutes SCT script using scrobj.dll from a command in entered into a specially prepared INF file.
windows · process_creation
Lolbin Runexehelper Use As Proxy
mediumDetect usage of the "runexehelper.exe" binary as a proxy to launch other programs
windows · process_creation
Lolbin Unregmp2.exe Use As Proxy
mediumDetect usage of the "unregmp2.exe" binary as a proxy to launch a custom version of "wmpnscfg.exe"
windows · process_creation
Malicious PE Execution by Microsoft Visual Studio Debugger
mediumThere is an option for a MS VS Just-In-Time Debugger "vsjitdebugger.exe" to launch specified executable and attach a debugger. This option may be used adversaries to execute malicious code by signed verified binary. The debugger is installed alongside with Microsoft Visual Studio package.
windows · process_creation
Microsoft Sync Center Suspicious Network Connections
mediumDetects suspicious connections from Microsoft Sync Center to non-private IPs.
windows · network_connection
Microsoft Workflow Compiler Execution
mediumDetects the execution of Microsoft Workflow Compiler, which may permit the execution of arbitrary unsigned code.
windows · process_creation
MMC Loading Script Engines DLLs
mediumDetects when the Microsoft Management Console (MMC) loads the DLL libraries like vbscript, jscript etc which might indicate an attempt to execute malicious scripts within a trusted system process for bypassing application whitelisting or defense evasion.
windows · image_load
MSI Installation From Web
mediumDetects installation of a remote msi file from web.
windows
Msiexec Quiet Installation
mediumAdversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi)
windows · process_creation
MsiExec Web Install
mediumDetects suspicious msiexec process starts with web addresses as parameter
windows · process_creation
Network Connection Initiated By Regsvr32.EXE
mediumDetects a network connection initiated by "Regsvr32.exe"
windows · network_connection
New Capture Session Launched Via DXCap.EXE
mediumDetects the execution of "DXCap.EXE" with the "-c" flag, which allows a user to launch any arbitrary binary or windows package through DXCap itself. This can be abused to potentially bypass application whitelisting.
windows · process_creation
New DLL Registered Via Odbcconf.EXE
mediumDetects execution of "odbcconf" with "REGSVR" in order to register a new DLL (equivalent to running regsvr32). Attackers abuse this to install and run malicious DLLs.
windows · process_creation
New Self Extracting Package Created Via IExpress.EXE
mediumDetects the "iexpress.exe" utility creating self-extracting packages. Attackers where seen leveraging "iexpress" to compile packages on the fly via ".sed" files. Investigate the command line options provided to "iexpress" and in case of a ".sed" file, check the contents and legitimacy of it.
windows · process_creation
Outbound Network Connection To Public IP Via Winlogon
mediumDetects a "winlogon.exe" process that initiate network communications with public IP addresses
windows · network_connection
Potential Application Whitelisting Bypass via Dnx.EXE
mediumDetects the execution of Dnx.EXE. The Dnx utility allows for the execution of C# code. Attackers might abuse this in order to bypass application whitelisting.
windows · process_creation
Potential APT-C-12 BlueMushroom DLL Load Activity Via Regsvr32
mediumDetects potential BlueMushroom DLL loading activity via regsvr32 from AppData Local
windows · process_creation
Potential Arbitrary File Download Via Cmdl32.EXE
mediumDetects execution of Cmdl32 with the "/vpn" and "/lan" flags. Attackers can abuse this utility in order to download arbitrary files via a configuration file. Inspect the location and the content of the file passed as an argument in order to determine if it is suspicious.
windows · process_creation
Potential Binary Impersonating Sysinternals Tools
mediumDetects binaries that use the same name as legitimate sysinternals tools to evade detection. This rule looks for the execution of binaries that are named similarly to Sysinternals tools. Adversary may rename their malicious tools as legitimate Sysinternals tools to evade detection.
windows · process_creation
Potential Binary Proxy Execution Via Cdb.EXE
mediumDetects usage of "cdb.exe" to launch arbitrary processes or commands from a debugger script file
windows · process_creation
Potential Binary Proxy Execution Via VSDiagnostics.EXE
mediumDetects execution of "VSDiagnostics.exe" with the "start" command in order to launch and proxy arbitrary binaries.
windows · process_creation
Potential DLL Sideloading Activity Via ExtExport.EXE
mediumDetects the execution of "Extexport.exe".A utility that is part of the Internet Explorer browser and is used to export and import various settings and data, particularly when switching between Internet Explorer and other web browsers like Firefox. It allows users to transfer bookmarks, browsing history, and other preferences from Internet Explorer to Firefox or vice versa. It can be abused as a tool to side load any DLL. If a folder is provided in the command line it'll load any DLL with one of the following names "mozcrt19.dll", "mozsqlite3.dll", or "sqlite.dll". Arbitrary DLLs can also be loaded if a specific number of flags was provided.
windows · process_creation
Potential DLL Sideloading Using Coregen.exe
mediumDetect usage of the "coregen.exe" (Microsoft CoreCLR Native Image Generator) binary to sideload arbitrary DLLs.
windows · image_load
Potential File Download Via MS-AppInstaller Protocol Handler
mediumDetects usage of the "ms-appinstaller" protocol handler via command line to potentially download arbitrary files via AppInstaller.EXE The downloaded files are temporarly stored in ":\Users\%username%\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\AC\INetCache\<RANDOM-8-CHAR-DIRECTORY>"
windows · process_creation
Potential Mpclient.DLL Sideloading Via OfflineScannerShell.EXE Execution
mediumDetects execution of Windows Defender "OfflineScannerShell.exe" from its non standard directory. The "OfflineScannerShell.exe" binary is vulnerable to DLL side loading and will load any DLL named "mpclient.dll" from the current working directory.
windows · process_creation
Potential Password Spraying Attempt Using Dsacls.EXE
mediumDetects possible password spraying attempts using Dsacls
windows · process_creation
Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE
mediumDetects the execution of concatenated commands via "cmd.exe". Pikabot often executes a combination of multiple commands via the command handler "cmd /c" in order to download and execute additional payloads. Commands such as "curl", "wget" in order to download extra payloads. "ping" and "timeout" are abused to introduce delays in the command execution and "Rundll32" is also used to execute malicious DLL files. In the observed Pikabot infections, a combination of the commands described above are used to orchestrate the download and execution of malicious DLL files.
windows · process_creation
Potential Provlaunch.EXE Binary Proxy Execution Abuse
mediumDetects child processes of "provlaunch.exe" which might indicate potential abuse to proxy execution.
windows · process_creation
Potential Register_App.Vbs LOLScript Abuse
mediumDetects potential abuse of the "register_app.vbs" script that is part of the Windows SDK. The script offers the capability to register new VSS/VDS Provider as a COM+ application. Attackers can use this to install malicious DLLs for persistence and execution.
windows · process_creation
Potential Regsvr32 Commandline Flag Anomaly
mediumDetects a potential command line flag anomaly related to "regsvr32" in which the "/i" flag is used without the "/n" which should be uncommon.
windows · process_creation
Potentially Over Permissive Permissions Granted Using Dsacls.EXE
mediumDetects usage of Dsacls to grant over permissive permissions
windows · process_creation
Potentially Suspicious Cabinet File Expansion
mediumDetects the expansion or decompression of cabinet files from potentially suspicious or uncommon locations, e.g. seen in Iranian MeteorExpress related attacks
windows · process_creation
Potentially Suspicious Child Process Of DiskShadow.EXE
mediumDetects potentially suspicious child processes of "Diskshadow.exe". This could be an attempt to bypass parent/child relationship detection or application whitelisting rules.
windows · process_creation
Potentially Suspicious Child Process Of VsCode
mediumDetects uncommon or suspicious child processes spawning from a VsCode "code.exe" process. This could indicate an attempt of persistence via VsCode tasks or terminal profiles.
windows · process_creation
Potentially Suspicious CMD Shell Output Redirect
mediumDetects inline Windows shell commands redirecting output via the ">" symbol to a suspicious location. This technique is sometimes used by malicious actors in order to redirect the output of reconnaissance commands such as "hostname" and "dir" to files for future exfiltration.
windows · process_creation
Potentially Suspicious Execution Of Regasm/Regsvcs From Uncommon Location
mediumDetects potentially suspicious execution of the Regasm/Regsvcs utilities from a potentially suspicious location
windows · process_creation
Potentially Suspicious Execution Of Regasm/Regsvcs With Uncommon Extension
mediumDetects potentially suspicious execution of the Regasm/Regsvcs utilities with an uncommon extension.
windows · process_creation
Potentially Suspicious Regsvr32 HTTP/FTP Pattern
mediumDetects regsvr32 execution to download/install/register new DLLs that are hosted on Web or FTP servers.
windows · process_creation
Potentially Suspicious Rundll32 Activity
mediumDetects suspicious execution of rundll32, with specific calls to some DLLs with known LOLBIN functionalities
windows · process_creation
Potentially Suspicious Rundll32.EXE Execution of UDL File
mediumDetects the execution of rundll32.exe with the oledb32.dll library to open a UDL file. Threat actors can abuse this technique as a phishing vector to capture authentication credentials or other sensitive data.
windows · process_creation
Potentially Suspicious Self Extraction Directive File Created
mediumDetects the creation of a binary file with the ".sed" extension. The ".sed" extension stand for Self Extraction Directive files. These files are used by the "iexpress.exe" utility in order to create self extracting packages. Attackers were seen abusing this utility and creating PE files with embedded ".sed" entries. Usually ".sed" files are simple ini files and not PE binaries.
windows · file_executable_detected
Potentially Suspicious Wuauclt Network Connection
mediumDetects the use of the Windows Update Client binary (wuauclt.exe) to proxy execute code and making network connections. One could easily make the DLL spawn a new process and inject to it to proxy the network connection and bypass this rule.
windows · network_connection
PowerShell MSI Install via WindowsInstaller COM From Remote Location
mediumDetects the execution of PowerShell commands that attempt to install MSI packages via the Windows Installer COM object (`WindowsInstaller.Installer`) hosted remotely. This could be indication of malicious software deployment or lateral movement attempts using Windows Installer functionality. And the usage of WindowsInstaller COM object rather than msiexec could be an attempt to bypass the detection.
windows · process_creation
PowerShell WMI Win32_Product Install MSI
mediumDetects the execution of an MSI file using PowerShell and the WMI Win32_Product class
windows · ps_script
Process Memory Dump Via Dotnet-Dump
mediumDetects the execution of "dotnet-dump" with the "collect" flag. The execution could indicate potential process dumping of critical processes such as LSASS.
windows · process_creation
Process Proxy Execution Via Squirrel.EXE
mediumDetects the usage of the "Squirrel.exe" binary to execute arbitrary processes. This binary is part of multiple Electron based software installations (Slack, Teams, Discord, etc.)
windows · process_creation
Program Executed Using Proxy/Local Command Via SSH.EXE
mediumDetect usage of the "ssh.exe" binary as a proxy to launch other programs.
windows · process_creation
RegAsm.EXE Initiating Network Connection To Public IP
mediumDetects "RegAsm.exe" initiating a network connection to public IP adresses
windows · network_connection
REGISTER_APP.VBS Proxy Execution
mediumDetects the use of a Microsoft signed script 'REGISTER_APP.VBS' to register a VSS/VDS Provider as a COM+ application.
windows · process_creation
Regsvr32 Execution From Potential Suspicious Location
mediumDetects execution of regsvr32 where the DLL is located in a potentially suspicious location.
windows · process_creation
Regsvr32.EXE Calling of DllRegisterServer Export Function Implicitly
mediumDetects execution of regsvr32 with the silent flag and no other flags on a DLL located in an uncommon or potentially suspicious location. When Regsvr32 is called in such a way, it implicitly calls the DLL export function 'DllRegisterServer'.
windows · process_creation
Remote File Download Via Findstr.EXE
mediumDetects execution of "findstr" with specific flags and a remote share path. This specific set of CLI flags would allow "findstr" to download the content of the file located on the remote share as described in the LOLBAS entry.
windows · process_creation
Remote Thread Creation Via PowerShell In Uncommon Target
mediumDetects the creation of a remote thread from a Powershell process in an uncommon target process
windows · create_remote_thread
Response File Execution Via Odbcconf.EXE
mediumDetects execution of "odbcconf" with the "-f" flag in order to load a response file which might contain a malicious action.
windows · process_creation
Rhadamanthys Stealer Module Launch Via Rundll32.EXE
mediumDetects the use of Rundll32 to launch an NSIS module that serves as the main stealer capability of Rhadamanthys infostealer, as observed in reports and samples in early 2023
windows · process_creation
Rundll32 Execution With Uncommon DLL Extension
mediumDetects the execution of rundll32 with a command line that doesn't contain a common extension
windows · process_creation
Rundll32 InstallScreenSaver Execution
mediumAn attacker may execute an application as a SCR File using rundll32.exe desk.cpl,InstallScreenSaver
windows · process_creation
Rundll32 Internet Connection
mediumDetects a rundll32 that communicates with public IP addresses
windows · network_connection
Rundll32.EXE Calling DllRegisterServer Export Function Explicitly
mediumDetects when the DLL export function 'DllRegisterServer' is called in the commandline by Rundll32 explicitly where the DLL is located in a non-standard path.
windows · process_creation
Scheduled Task Creation with Curl and PowerShell Execution Combo
mediumDetects the creation of a scheduled task using schtasks.exe, potentially in combination with curl for downloading payloads and PowerShell for executing them. This facilitates executing malicious payloads or connecting with C&C server persistently without dropping the malware sample on the host.
windows · process_creation
SCR File Write Event
mediumDetects the creation of screensaver files (.scr) outside of system folders. Attackers may execute an application as an ".SCR" file using "rundll32.exe desk.cpl,InstallScreenSaver" for example.
windows · file_event
ScreenSaver Registry Key Set
mediumDetects registry key established after masqueraded .scr file execution using Rundll32 through desk.cpl
windows · registry_set
Scripting/CommandLine Process Spawned Regsvr32
mediumDetects various command line and scripting engines/processes such as "PowerShell", "Wscript", "Cmd", etc. spawning a "regsvr32" instance.
windows · process_creation
Self Extraction Directive File Created In Potentially Suspicious Location
mediumDetects the creation of Self Extraction Directive files (.sed) in a potentially suspicious location. These files are used by the "iexpress.exe" utility in order to create self extracting packages. Attackers were seen abusing this utility and creating PE files with embedded ".sed" entries.
windows · file_event
Suspicious Csi.exe Usage
mediumCsi.exe is a signed binary from Microsoft that comes with Visual Studio and provides C# interactive capabilities. It can be used to run C# code from a file passed as a parameter in command line. Early version of this utility provided with Microsoft “Roslyn” Community Technology Preview was named 'rcsi.exe'
windows · process_creation
Suspicious MsiExec Embedding Parent
mediumAdversaries may abuse msiexec.exe to proxy the execution of malicious payloads
windows · process_creation
Suspicious Msiexec Execute Arbitrary DLL
mediumAdversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi)
windows · process_creation
Suspicious Msiexec Quiet Install From Remote Location
mediumDetects usage of Msiexec.exe to install packages hosted remotely quietly
windows · process_creation
Suspicious Rundll32 Setupapi.dll Activity
mediumsetupapi.dll library provide InstallHinfSection function for processing INF files. INF file may contain instructions allowing to create values in the registry, modify files and install drivers. This technique could be used to obtain persistence via modifying one of Run or RunOnce registry keys, run process or use other DLLs chain calls (see references) InstallHinfSection function in setupapi.dll calls runonce.exe executable regardless of actual content of INF file.
windows · process_creation
Suspicious Vsls-Agent Command With AgentExtensionPath Load
mediumDetects Microsoft Visual Studio vsls-agent.exe lolbin execution with a suspicious library load using the --agentExtensionPath parameter
windows · process_creation
Suspicious ZipExec Execution
mediumZipExec is a Proof-of-Concept (POC) tool to wrap binary-based tools into a password-protected zip file.
windows · process_creation
SyncAppvPublishingServer Bypass Powershell Restriction - PS Module
mediumDetects SyncAppvPublishingServer process execution which usually utilized by adversaries to bypass PowerShell execution restrictions.
windows · ps_module
SyncAppvPublishingServer Execute Arbitrary PowerShell Code
mediumExecutes arbitrary PowerShell code using SyncAppvPublishingServer.exe.
windows · process_creation
SyncAppvPublishingServer Execution to Bypass Powershell Restriction
mediumDetects SyncAppvPublishingServer process execution which usually utilized by adversaries to bypass PowerShell execution restrictions.
windows · ps_script
SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code
mediumExecutes arbitrary PowerShell code using SyncAppvPublishingServer.vbs
windows · process_creation
Uncommon Assistive Technology Applications Execution Via AtBroker.EXE
mediumDetects the start of a non built-in assistive technology applications via "Atbroker.EXE".
windows · process_creation
Uncommon AddinUtil.EXE CommandLine Execution
mediumDetects execution of the Add-In deployment cache updating utility (AddInutil.exe) with uncommon Addinroot or Pipelineroot paths. An adversary may execute AddinUtil.exe with uncommon Addinroot/Pipelineroot paths that point to the adversaries Addins.Store payload.
windows · process_creation
Uncommon Child Process Of AddinUtil.EXE
mediumDetects uncommon child processes of the Add-In deployment cache updating utility (AddInutil.exe) which could be a sign of potential abuse of the binary to proxy execution via a custom Addins.Store payload.
windows · process_creation
Uncommon Child Process Of Appvlp.EXE
mediumDetects uncommon child processes of Appvlp.EXE Appvlp or the Application Virtualization Utility is included with Microsoft Office. Attackers are able to abuse "AppVLP" to execute shell commands. Normally, this binary is used for Application Virtualization, but it can also be abused to circumvent the ASR file path rule folder or to mark a file as a system file.
windows · process_creation
Uncommon Child Process Of BgInfo.EXE
mediumDetects uncommon child processes of "BgInfo.exe" which could be a sign of potential abuse of the binary to proxy execution via external VBScript
windows · process_creation
Uncommon Child Process Of Defaultpack.EXE
mediumDetects uncommon child processes of "DefaultPack.EXE" binary as a proxy to launch other programs
windows · process_creation
Uncommon Child Process Spawned By Odbcconf.EXE
mediumDetects an uncommon child process of "odbcconf.exe" binary which normally shouldn't have any child processes.
windows · process_creation
Uncommon Link.EXE Parent Process
mediumDetects an uncommon parent process of "LINK.EXE". Link.EXE in Microsoft incremental linker. Its a utility usually bundled with Visual Studio installation. Multiple utilities often found in the same folder (editbin.exe, dumpbin.exe, lib.exe, etc) have a hardcode call to the "LINK.EXE" binary without checking its validity. This would allow an attacker to sideload any binary with the name "link.exe" if one of the aforementioned tools get executed from a different location. By filtering the known locations of such utilities we can spot uncommon parent process of LINK.EXE that might be suspicious or malicious.
windows · process_creation
Unsigned DLL Loaded by Windows Utility
mediumDetects windows utilities loading an unsigned or untrusted DLL. Adversaries often abuse those programs to proxy execution of malicious code.
windows · image_load
Use of Scriptrunner.exe
mediumThe "ScriptRunner.exe" binary can be abused to proxy execution through it and bypass possible whitelisting
windows · process_creation
Use Of The SFTP.EXE Binary As A LOLBIN
mediumDetects the usage of the "sftp.exe" binary as a LOLBIN by abusing the "-D" flag
windows · process_creation
Use of VisualUiaVerifyNative.exe
mediumVisualUiaVerifyNative.exe is a Windows SDK that can be used for AWL bypass and is listed in Microsoft's recommended block rules.
windows · process_creation
Verclsid.exe Runs COM Object
mediumDetects when verclsid.exe is used to run COM object via GUID
windows · process_creation
Visual Studio NodejsTools PressAnyKey Arbitrary Binary Execution
mediumDetects child processes of Microsoft.NodejsTools.PressAnyKey.exe that can be used to execute any other binary
windows · process_creation
Visual Studio NodejsTools PressAnyKey Renamed Execution
mediumDetects renamed execution of "Microsoft.NodejsTools.PressAnyKey.exe", which can be abused as a LOLBIN to execute arbitrary binaries
windows · process_creation
Wlrmdr.EXE Uncommon Argument Or Child Process
mediumDetects the execution of "Wlrmdr.exe" with the "-u" command line flag which allows anything passed to it to be an argument of the ShellExecute API, which would allow an attacker to execute arbitrary binaries. This detection also focuses on any uncommon child processes spawned from "Wlrmdr.exe" as a supplement for those that posses "ParentImage" telemetry.
windows · process_creation
WSL Child Process Anomaly
mediumDetects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL
windows · process_creation
XBAP Execution From Uncommon Locations Via PresentationHost.EXE
mediumDetects the execution of ".xbap" (Browser Applications) files via PresentationHost.EXE from an uncommon location. These files can be abused to run malicious ".xbap" files any bypass AWL
windows · process_creation
BitLockerTogo.EXE Execution
lowDetects the execution of "BitLockerToGo.EXE". BitLocker To Go is BitLocker Drive Encryption on removable data drives. This feature includes the encryption of, USB flash drives, SD cards, External hard disk drives, Other drives that are formatted by using the NTFS, FAT16, FAT32, or exFAT file system. This is a rarely used application and usage of it at all is worth investigating. Malware such as Lumma stealer has been seen using this process as a target for process hollowing.
windows · process_creation
HH.EXE Execution
lowDetects the execution of "hh.exe" to open ".chm" files.
windows · process_creation
Indirect Command Execution By Program Compatibility Wizard
lowDetect indirect command execution via Program Compatibility Assistant pcwrun.exe
windows · process_creation
Insensitive Subfolder Search Via Findstr.EXE
lowDetects execution of findstr with the "s" and "i" flags for a "subfolder" and "insensitive" search respectively. Attackers sometimes leverage this built-in utility to search the system for interesting files or filter through results of commands.
windows · process_creation
Malicious Windows Script Components File Execution by TAEF Detection
lowWindows Test Authoring and Execution Framework (TAEF) framework allows you to run automation by executing tests files written on different languages (C, C#, Microsoft COM Scripting interfaces Adversaries may execute malicious code (such as WSC file with VBScript, dll and so on) directly by running te.exe
windows · process_creation
Msiexec.EXE Initiated Network Connection Over HTTP
lowDetects a network connection initiated by an "Msiexec.exe" process over port 80 or 443. Adversaries might abuse "msiexec.exe" to install and execute remotely hosted packages. Use this rule to hunt for potentially anomalous or suspicious communications.
windows · network_connection
Potential Proxy Execution Via Explorer.EXE From Shell Process
lowDetects the creation of a child "explorer.exe" process from a shell like process such as "cmd.exe" or "powershell.exe". Attackers can use "explorer.exe" for evading defense mechanisms by proxying the execution through the latter. While this is often a legitimate action, this rule can be use to hunt for anomalies. Muddy Waters threat actor was seeing using this technique.
windows · process_creation
RegAsm.EXE Execution Without CommandLine Flags or Files
lowDetects the execution of "RegAsm.exe" without a commandline flag or file, which might indicate potential process injection activity. Usually "RegAsm.exe" should point to a dedicated DLL file or call the help with the "/?" flag.
windows · process_creation
Windows MSIX Package Support Framework AI_STUBS Execution
lowDetects execution of Advanced Installer MSIX Package Support Framework (PSF) components, specifically AI_STUBS executables with original filename 'popupwrapper.exe'. This activity may indicate malicious MSIX packages build with Advanced Installer leveraging the Package Support Framework to bypass application control restrictions.
windows · process_creation