T1218 System Binary Proxy Execution
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system.(Citation: LOLBAS Project) Binaries signed with trusted digital…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- APT29 2018 Phishing Campaign CommandLine Indicatorscriticalstable · windows
- APT29 2018 Phishing Campaign File Indicatorscriticalstable · windows
- Equation Group DLL_U Export Function Loadcriticalstable · windows
- EvilNum APT Golden Chickens Deployment Via OCX Filescriticaltest · windows
- HackTool - F-Secure C3 Load by Rundll32criticaltest · windows
- NotPetya Ransomware Activitycriticaltest · windows
- Potential Emotet Rundll32 Executioncriticaltest · windows
- ZxShell Malwarecriticaltest · windows
- CMSTP Execution Process Accesshighstable · windows
- CMSTP Execution Process Creationhighstable · windows
- CMSTP Execution Registry Eventhighstable · windows
- CMSTP UAC Bypass via COM Object Accesshighstable · windows
- Arbitrary File Download Via IMEWDBLD.EXEhightest · windows
- Bad Opsec Defaults Sacrificial Processes With Improper Argumentshightest · windows
- Bypass UAC via CMSTPhightest · windows
- CobaltStrike Load by Rundll32hightest · windows
- Control Panel Itemshightest · windows
- Csc.EXE Execution Form Potentially Suspicious Parenthightest · windows
- Curl Download And Execute Combinationhightest · windows
- DLL Loaded From Suspicious Location Via Cmspt.EXEhightest · windows
- Devtoolslauncher.exe Executes Specified Binaryhightest · windows
- Execute Pcwrun.EXE To Leverage Follinahightest · windows
- Execution DLL of Choice Using WAB.EXEhightest · windows
- Execution via WorkFolders.exehightest · windows
- Execution via stordiag.exehightest · windows
Mostrando 25 de 137.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.