{"id":"T1216.002","name":"SyncAppvPublishingServer","url":"https://attack.mitre.org/techniques/T1216/002","tactics":["stealth"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0440","stix_id":"x-mitre-detection-strategy--ba3578d1-5913-4ed1-ab83-473a39b63f7d","name":"Detecting PowerShell Execution via SyncAppvPublishingServer.vbs Proxy Abuse","url":"https://attack.mitre.org/detectionstrategies/DET0440","analytics":[{"id":"AN1220","stix_id":"x-mitre-analytic--a59042de-ecac-45bf-a852-af3df41b86d8","name":"Analytic 1220","description":"Execution of SyncAppvPublishingServer.vbs through wscript.exe with a command-line containing embedded PowerShell, proxying malicious PowerShell execution through a Microsoft-signed VBScript interpreter to evade detection and restrictions.","url":"https://attack.mitre.org/detectionstrategies/DET0440#AN1220","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"CommandLineRegex","description":"Detects embedded PowerShell commands in SyncAppvPublishingServer.vbs invocation, e.g., `{powershell -nop -enc ...}`"},{"field":"ScriptInterpreter","description":"May vary between `wscript.exe`, `cscript.exe`, or called via `cmd.exe`"},{"field":"PowerShellObfuscationScore","description":"Used to detect encoding, obfuscation, or entropy level in embedded PowerShell payloads"},{"field":"TimeWindow","description":"Time delta between VBScript proxy invocation and PowerShell payload execution"}],"live":true,"detection_strategies":["DET0440"],"techniques":["T1216.002"]}],"live":true,"version":"1.0","techniques":["T1216.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}