WindowsT1218.015

>Mscopilot_proxy.exe

Microsoft Copilot proxy launcher

Default Executable Paths

C:\Program Files (x86)\Microsoft\Copilot\Application\mscopilot_proxy.exe

Integrity & Metadata

Category Count: 1 weaponized patterns
Forensics & Triage Insight

Documented in LOLBAS project by 4n4s4zi.

Detection Engineering Notes

Monitor process creation events where FileName is "Mscopilot_proxy.exe" or command line references known attack arguments.

Executive Summary & AI Quick Reference

High-Fidelity Telemetry Profile

Mscopilot_proxy.exe is a native utility pre-installed on Windows systems. Threat actors and red teams abuse Mscopilot_proxy.exe as a Living-off-the-Land Binary (LOLBin) to achieve Execute without triggering traditional antivirus file-hash alerts. Legitimate system administrators use it for routine administration, making behavioral command-line telemetry essential for differentiation.

Primary Abused Tactics
Execute
Minimum Privilege
User
Key Telemetry Source
Sysmon 1 / 4688
ATT&CK Mapping
T1218.015

Weaponized Parameters & Proof-of-Concepts

Documented attack commands, parameter flags, and privilege prerequisites.

1 documented methods
Filter Purpose:
ExecutePrivileges: User
T1218.015: Technique T1218.015

`mscopilot_proxy.exe` will spawn the provided command. Parent `mscopilot_proxy.exe` process needs to be killed to avoid command being executed an infinite number of times.

mscopilot_proxy.exe --no-startup-window --disable-gpu-sandbox --gpu-launcher="cmd.exe /c calc.exe && taskkill /f /im mscopilot.exe &&"

SIEM & EDR Detection Rules

Production telemetry rules configured for Microsoft Defender, Sigma, and Splunk.

Telemetry & SIEM Detection Suite (Mscopilot_proxy.exe)

Validated against MITRE T1218.015
Mscopilot_proxy.exe Microsoft Defender Querykql
1// Microsoft Defender XDR / Microsoft Sentinel
2// Tactic: Execute
3DeviceProcessEvents
4| where FileName =~ "Mscopilot_proxy.exe"
5| where ProcessCommandLine has_any ("Mscopilot_proxy")
6| project
7 Timestamp,
8 DeviceName,
9 AccountName,
10 InitiatingProcessParentFileName,
11 InitiatingProcessFileName,
12 InitiatingProcessCommandLine,
13 FileName,
14 FolderPath,
15 ProcessCommandLine,
16 MD5,
17 SHA256
18| sort by Timestamp desc

Mitigation, Hardening & Prevention

Recommended defensive controls to block or constrain Mscopilot_proxy.exe abuse.

Application Whitelisting

Enforce Windows Defender Application Control (WDAC) or AppLocker publisher rules to prevent execution outside approved enterprise administration scripts.

Attack Surface Reduction

Enable ASR rules: Block executable content from email client and webmail and Block Office applications from creating child processes spawning Mscopilot_proxy.exe.

Behavioral Alerting

Deploy the KQL, Sigma, and Splunk detection queries below. Alert on anomalous child processes, web requests to unrated external IPs, or encoded payload strings.

Frequently Asked Questions (FAQ) • Mscopilot_proxy.exe

Key operational questions and defensive answers about Mscopilot_proxy.exe LOLBin tradecraft.

What is Mscopilot_proxy.exe and why is it classified as a LOLBin?

Mscopilot_proxy.exe is a legitimate, pre-installed or trusted utility on Windows. It is classified as a Living-off-the-Land Binary (LOLBin) because adversaries abuse its built-in functionality to perform malicious operations—such as Execute—without dropping custom malware binaries on disk.

How do threat actors abuse Mscopilot_proxy.exe in cyber intrusions?

Adversaries leverage Mscopilot_proxy.exe to execute stealthy actions while evading signature-based security controls. For example, attackers execute commands like "mscopilot_proxy.exe --no-startup-window --disable-gpu-sandbox --gpu-launcher="cmd.exe /c calc.exe && taskkill /f /im mscopilot.exe &&"" to achieve Execute, masquerading behind legitimate system process lineage.

How can SOC analysts detect suspicious Mscopilot_proxy.exe activity?

Detection engineers monitor process creation events (Windows Event ID 4688 or Sysmon Event ID 1; Linux auditd EXECVE; macOS Endpoint Security) inspecting anomalous command line arguments, unusual parent-child process relationships (e.g. Office apps or web servers spawning Mscopilot_proxy.exe), and unexpected network connections.

What MITRE ATT&CK techniques does Mscopilot_proxy.exe map to?

Mscopilot_proxy.exe maps to MITRE ATT&CK technique(s): T1218.015. These techniques cover adversary actions across tactics such as Defense Evasion, Execution, Persistence, and Command and Control.

How can organizations mitigate and restrict Mscopilot_proxy.exe?

Mitigation strategies include implementing Application Control policies (AppLocker or Windows Defender Application Control - WDAC), enforcing Attack Surface Reduction (ASR) rules, configuring strict privilege separation (disallowing standard users from running sensitive switches), and alerting on execution from non-standard directories.

Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point