kevmap

Techniques › T1216

T1216 System Script Proxy Execution

stealth — Windows · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
13
Sigma rules tagged attack.t1216
0
KEV CVEs mapped here
<p>Adversaries may use trusted scripts, often signed with certificates, to proxy the execution of malicious files. Several Microsoft signed scripts that have been downloaded from Microsoft or are default on Windows installations can be used to proxy execution of other files. This behavior may be abused by adversaries to execute malicious files that could bypass application control and signature validation on systems.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1216

Author: frack113 · 2022-05-28 · logsource: product=windows category=process_creation · 0403d67d-6227-4ea8-8145-4e72db7da120
Detects the use of a Microsoft signed script executing a managed DLL with PowerShell.
Techniques: T1216
Author: Julia Fomina, oscd.community · 2020-10-06 (modified 2022-10-09) · logsource: product=windows category=process_creation · 074e0ded-6ced-4ebd-8b4d-53f55908119d
Detects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)
Techniques: T1216
Author: frack113, Nasreddine Bencherchali · 2022-08-20 · logsource: product=windows category=process_creation · 18988e1b-9087-4f8a-82fe-0414dce49878
Detects code execution via Pester.bat (Pester - Powershell Modulte for testing)
Techniques: T1059.001T1216
Author: Nasreddine Bencherchali (Nextron Systems), oscd.community, Natalia Shornikova, frack113 · 2022-05-21 (modified 2023-08-17) · logsource: product=windows category=process_creation · 1e0e1a81-e79b-44bc-935b-ddb9c8006b3d
Detects the use of the Microsoft signed script "CL_mutexverifiers" to proxy the execution of additional PowerShell script commands
Techniques: T1216
Author: frack113 · 2021-07-16 (modified 2022-06-22) · logsource: product=windows category=process_creation · 36475a7d-0f6d-4dce-9b01-6aeb473bbaf1
Executes arbitrary PowerShell code using SyncAppvPublishingServer.vbs
Techniques: T1218T1216
Author: Julia Fomina, oscd.community · 2020-10-08 (modified 2023-11-09) · logsource: product=windows category=process_creation · 59e938ff-0d6d-4dc3-b13f-36cc28734d4e
Detects code execution via Pester.bat (Pester - Powershell Modulte for testing)
Techniques: T1059.001T1216
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-08-19 (modified 2024-08-27) · logsource: product=windows category=process_creation · 7d4aaec2-08ed-4430-8b96-28420e030e04
Detects uncommon child processes spawning from "sigverif.exe", which could indicate potential abuse of the latter as a living of the land binary in order to proxy execution.
Techniques: T1216
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-08-19 (modified 2025-10-29) · logsource: product=windows category=process_creation · 84b14121-9d14-416e-800b-f3b829c5a14d
Detects the execution of CustomShellHost.exe where the child isn't located in 'C:\Windows\explorer.exe'. CustomShellHost is a known LOLBin that can be abused by attackers for defense evasion techniques.
Techniques: T1216
Author: Julia Fomina, oscd.community · 2020-10-07 (modified 2023-03-03) · logsource: product=windows category=process_creation · 9df0dd3a-1a5c-47e3-a2bc-30ed177646a0
Detects an attempt to execute code or create service on remote host via winrm.vbs.
Techniques: T1216
Author: Nasreddine Bencherchali (Nextron Systems), oscd.community, Natalia Shornikova · 2020-10-14 (modified 2023-08-17) · logsource: product=windows category=process_creation · a0459f02-ac51-4c09-b511-b8c9203fc429
Detects calls to "SyncInvoke" that is part of the "CL_Invocation.ps1" script to proxy execution using "System.Diagnostics.Process"
Techniques: T1216
Author: oscd.community, Natalia Shornikova, Nasreddine Bencherchali (Nextron Systems) · 2020-10-13 (modified 2023-02-03) · logsource: product=windows category=process_creation · c363385c-f75d-4753-a108-c1a8e28bdbda
Detects potential abuse of the "manage-bde.wsf" script as a LOLBIN to proxy execution
Techniques: T1216
Author: frack113, Nasreddine Bencherchali (Nextron Systems) · 2022-05-21 (modified 2023-08-17) · logsource: product=windows category=process_creation · c57872c7-614f-4d7f-a40d-b78c8df2d30d
Detects calls to "LoadAssemblyFromPath" or "LoadAssemblyFromNS" that are part of the "CL_LoadAssembly.ps1" script. This can be abused to load different assemblies and bypass App locker controls.
Techniques: T1216
Author: Julia Fomina, oscd.community · 2020-10-06 (modified 2022-11-28) · logsource: product=windows category=file_event · d353dac0-1b41-46c2-820c-d7d2561fc6ed
Detects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)
Techniques: T1216

Sub-techniques

IDNameSigma rulesKEV CVEs
T1216.001PubPrn20
T1216.002SyncAppvPublishingServer00