{"id":"T1216.001","name":"PubPrn","url":"https://attack.mitre.org/techniques/T1216/001","tactics":["stealth"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0528","stix_id":"x-mitre-detection-strategy--4e2e06c5-a7bd-40d9-af9b-99fdfe725360","name":"Detecting Remote Script Proxy Execution via PubPrn.vbs","url":"https://attack.mitre.org/detectionstrategies/DET0528","analytics":[{"id":"AN1464","stix_id":"x-mitre-analytic--e7444be7-3c0a-4ff2-927d-f623af05936d","name":"Analytic 1464","description":"Execution of PubPrn.vbs via cscript.exe using the 'script:' moniker to load and execute a remote .sct scriptlet file, bypassing signature validation and proxying remote payloads through a signed Microsoft script host.","url":"https://attack.mitre.org/detectionstrategies/DET0528#AN1464","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"CommandLineRegex","description":"Detects 'script:' moniker with HTTP/HTTPS URI as argument to pubprn.vbs"},{"field":"ParentProcessName","description":"May vary between cscript.exe, wscript.exe, or cmd.exe depending on execution method"},{"field":"NetworkDestinationDomain","description":"Used to detect external domains being contacted for remote scriptlet execution"},{"field":"TimeWindow","description":"Maximum allowed time delta between pubprn.vbs invocation and network connection or child process"}],"live":true,"detection_strategies":["DET0528"],"techniques":["T1216.001"]}],"live":true,"version":"1.0","techniques":["T1216.001"]}],"sigma_rules":[{"id":"1fb76ab8-fa60-4b01-bddd-71e89bf555da","title":"Pubprn.vbs Proxy Execution","author":"frack113","status":"test","level":"medium","date":"2022-05-28","modified":null,"description":"Detects the use of the 'Pubprn.vbs' Microsoft signed script to execute commands.","references":["https://lolbas-project.github.io/lolbas/Scripts/Pubprn/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1216.001"],"path":"rules/windows/process_creation/proc_creation_win_lolbin_pubprn.yml","techniques":["T1216.001"],"cves":[]},{"id":"45d3a03d-f441-458c-8883-df101a3bb146","title":"Launch-VsDevShell.PS1 Proxy Execution","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-08-19","modified":null,"description":"Detects the use of the 'Launch-VsDevShell.ps1' Microsoft signed script to execute commands.","references":["https://twitter.com/nas_bench/status/1535981653239255040"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1216.001"],"path":"rules/windows/process_creation/proc_creation_win_lolbin_launch_vsdevshell.yml","techniques":["T1216.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}