T1218System Binary Proxy Execution
T1218 — System Binary Proxy Execution is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 21 detection use cases covering it and 121 threat-intel articles citing it.
Defense Evasion
21Use cases
121Articles
14Sub-techniques
1Tactic
Sub-techniques (14)
T1218.003 · CMSTPT1218.001 · Compiled HTML FileT1218.002 · Control PanelT1218.015 · Electron ApplicationsT1218.004 · InstallUtilT1218.013 · MavinjectT1218.014 · MMCT1218.005 · MshtaT1218.007 · MsiexecT1218.008 · OdbcconfT1218.009 · Regsvcs/RegasmT1218.010 · Regsvr32T1218.011 · Rundll32T1218.012 · Verclsid
Use cases covering this technique (21)
Office app spawning script/LOLBin child process [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Cisco NVM - Suspicious Network Connection From Process With No Args LOLBAS With Network Traffic Windows Advanced Installer MSIX with AI_STUBS Execution Windows AppLocker Block Events Windows AppLocker Execution from Uncommon Locations Windows AppLocker Privilege Escalation via Unauthorized Bypass Windows AppLocker Rare Application Launch Detection Windows BitLockerToGo Process Execution Windows BitLockerToGo with Network Activity Windows Diskshadow Proxy Execution Windows Execute Arbitrary Commands with MSDT Windows MSC EvilTwin Directory Path Manipulation Windows Proxy Execution of .NET Utilities via Scripts Windows Rasautou DLL Execution Windows System Script Proxy Execution Syncappvpublishingserver [LLM] cscript/wscript executing a script from .laravel_locale temp directory [LLM] DRILLAPP variant 2: Edge launched with --remote-debugging-port=9222 for CDP-based file download [LLM] Renamed MSBuild.exe executing inline .csproj from user-writable path [LLM] NosyDoor AppDomainManager hijack: UevAppMonitor.exe executing from non-standard pathArticles citing this technique (121)
crit ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories art-51
high Curiouser and Curiouser art-52
crit AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS art-55
high Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection art-91
crit Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS art-101
crit Begun, the Patch Wars have art-253
crit ESET Threat Report H1 2026 art-312
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-448
high DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear art-623
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-673
crit ESET Threat Report H2 2025 art-762
crit CISA KEV: CVE-2024-38226 — Microsoft Publisher Protection Mechanism Failure Vulnerability art-1253
high Defense in Depth art-1415
high Ethical hacking techniques art-1721
high Ethical Hacking: Top Tools art-1725
crit API Security Guide art-1774
high Securing the web (forward) art-1826
high Cybersecurity Hygiene 101 art-1847
crit Secure Python URL validation art-1960
high Securing PHP containers art-2105
crit CISA KEV: CVE-2014-6287 — Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability art-2461
med Python Poetry package manager and security integration with software composition analysis tool art-3283
crit XSS Attacks: The Next Wave art-3664
high A CEO's guide to Emacs art-3716