Sigma Rule Library

MITRE ATT&CK technique

System Binary Proxy Execution detection rulesT1218

System Binary Proxy Execution (T1218) is a MITRE ATT&CK technique in the Stealth tactic. This page lists the 255 community-maintained Sigma detection rules in the library mapped to T1218 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, macos.

Top products

Tactic