Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · stealth

T1218 System Binary Proxy Execution

Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system.(Citation: LOLBAS Project) Binaries signed with trusted digital…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

Showing 25 of 137.

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.