T1218System Binary Proxy Execution
T1218 — System Binary Proxy Execution is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 25 detection use cases covering it and 94 threat-intel articles citing it.
Defense Evasion
25Use cases
94Articles
14Sub-techniques
1Tactic
Sub-techniques (14)
T1218.003 · CMSTPT1218.001 · Compiled HTML FileT1218.002 · Control PanelT1218.015 · Electron ApplicationsT1218.004 · InstallUtilT1218.013 · MavinjectT1218.014 · MMCT1218.005 · MshtaT1218.007 · MsiexecT1218.008 · OdbcconfT1218.009 · Regsvcs/RegasmT1218.010 · Regsvr32T1218.011 · Rundll32T1218.012 · Verclsid
Use cases covering this technique (25)
Office app spawning script/LOLBin child process [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Cisco NVM - Suspicious Network Connection From Process With No Args LOLBAS With Network Traffic Windows Advanced Installer MSIX with AI_STUBS Execution Windows AppLocker Block Events Windows AppLocker Execution from Uncommon Locations Windows AppLocker Privilege Escalation via Unauthorized Bypass Windows AppLocker Rare Application Launch Detection Windows BitLockerToGo Process Execution Windows BitLockerToGo with Network Activity Windows Diskshadow Proxy Execution Windows Execute Arbitrary Commands with MSDT Windows MSC EvilTwin Directory Path Manipulation Windows Proxy Execution of .NET Utilities via Scripts Windows Rasautou DLL Execution Windows System Script Proxy Execution Syncappvpublishingserver [LLM] Bun runtime executed from temp directory by Python interpreter (Hades vF203 loader) [LLM] Bun runtime download from github.com/oven-sh during npm install (Gen-2 loader) [LLM] cscript/wscript executing a script from .laravel_locale temp directory [LLM] PowerShell copy masqueraded as Windows Terminal in %PROGRAMDATA% running 6202033.ps1 [LLM] DRILLAPP variant 2: Edge launched with --remote-debugging-port=9222 for CDP-based file download [LLM] Renamed MSBuild.exe executing inline .csproj from user-writable path [LLM] APT28 MacroMaze: Edge launched off-screen or headless to webhook.site by non-browser parent [LLM] NosyDoor AppDomainManager hijack: UevAppMonitor.exe executing from non-standard pathArticles citing this technique (94)
high Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility art-74
crit Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models art-87
crit Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload art-219
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-220
high DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear art-470
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-537
crit ESET Threat Report H2 2025 art-647
high Defense in Depth art-1278