T1218System Binary Proxy Execution
T1218 — System Binary Proxy Execution is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 22 detection use cases covering it and 157 threat-intel articles citing it.
Defense Evasion
22Use cases
157Articles
14Sub-techniques
1Tactic
Sub-techniques (14)
T1218.003 · CMSTPT1218.001 · Compiled HTML FileT1218.002 · Control PanelT1218.015 · Electron ApplicationsT1218.004 · InstallUtilT1218.013 · MavinjectT1218.014 · MMCT1218.005 · MshtaT1218.007 · MsiexecT1218.008 · OdbcconfT1218.009 · Regsvcs/RegasmT1218.010 · Regsvr32T1218.011 · Rundll32T1218.012 · Verclsid
Use cases covering this technique (22)
Office app spawning script/LOLBin child process [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Cisco NVM - Suspicious Network Connection From Process With No Args LOLBAS With Network Traffic Windows Advanced Installer MSIX with AI_STUBS Execution Windows AppLocker Block Events Windows AppLocker Execution from Uncommon Locations Windows AppLocker Privilege Escalation via Unauthorized Bypass Windows AppLocker Rare Application Launch Detection Windows BitLockerToGo Process Execution Windows BitLockerToGo with Network Activity Windows Diskshadow Proxy Execution Windows Execute Arbitrary Commands with MSDT Windows MSC EvilTwin Directory Path Manipulation Windows Proxy Execution of .NET Utilities via Scripts Windows Rasautou DLL Execution Windows System Script Proxy Execution Syncappvpublishingserver [LLM] cscript/wscript executing a script from .laravel_locale temp directory [LLM] PowerShell copy masqueraded as Windows Terminal in %PROGRAMDATA% running 6202033.ps1 [LLM] DRILLAPP variant 2: Edge launched with --remote-debugging-port=9222 for CDP-based file download [LLM] Renamed MSBuild.exe executing inline .csproj from user-writable path [LLM] NosyDoor AppDomainManager hijack: UevAppMonitor.exe executing from non-standard pathArticles citing this technique (157)
crit Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads art-06
crit CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking art-74
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75
crit Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller art-97
crit Begun, the Patch Wars have art-150
crit Winning 54% of the time art-214
crit ESET Threat Report H1 2026 art-221
crit When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website art-246
high Catan and Mouse art-261
high The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration art-312
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-402
high DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear art-590
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-640
crit ESET Threat Report H2 2025 art-732
crit CISA KEV: CVE-2024-38226 — Microsoft Publisher Protection Mechanism Failure Vulnerability art-1230
high Defense in Depth art-1391
high Ethical hacking techniques art-1698
high Ethical Hacking: Top Tools art-1702
crit API Security Guide art-1751
high Securing the web (forward) art-1803
high Cybersecurity Hygiene 101 art-1824
crit Secure Python URL validation art-1937
high Securing PHP containers art-2082
crit CISA KEV: CVE-2014-6287 — Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability art-2438
med Python Poetry package manager and security integration with software composition analysis tool art-3260
crit XSS Attacks: The Next Wave art-3641
high A CEO's guide to Emacs art-3693