1200KM / detection
T1127 Trusted Developer Utilities Proxy Execution — Detection Rules
Detection workspace for T1127 Trusted Developer Utilities Proxy Execution: 19 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Remote Thread Creation Ttdinject.exe Proxy · test · high · {"product":"windows","category":"create_remote_thread"}
- Suspicious File Created by ArcSOC.exe · experimental · high · {"category":"file_event","product":"windows"}
- AspNetCompiler Execution · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Child Process of AspNetCompiler · test · high · {"category":"process_creation","product":"windows"}
- Potentially Suspicious ASP.NET Compilation Via AspNetCompiler · test · high · {"category":"process_creation","product":"windows"}
- Potential Binary Proxy Execution Via Cdb.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Use of CSharp Interactive Console · test · high · {"category":"process_creation","product":"windows"}
- C# IL Code Compilation Via Ilasm.EXE · test · medium · {"product":"windows","category":"process_creation"}
- JScript Compiler Execution · test · low · {"product":"windows","category":"process_creation"}
- Kavremover Dropped Binary LOLBIN Usage · test · high · {"product":"windows","category":"process_creation"}
- Use of Remote.exe · test · medium · {"category":"process_creation","product":"windows"}
- Use of TTDInject.exe · test · medium · {"product":"windows","category":"process_creation"}
- Use of VSIISExeLauncher.exe · test · medium · {"category":"process_creation","product":"windows"}
- Use of Wfc.exe · test · medium · {"category":"process_creation","product":"windows"}
- Potential Mftrace.EXE Abuse · test · medium · {"category":"process_creation","product":"windows"}
- Detection of PowerShell Execution via Sqlps.exe · test · medium · {"category":"process_creation","product":"windows"}
- SQL Client Tools PowerShell Session Detection · test · medium · {"category":"process_creation","product":"windows"}
- Potential Arbitrary Code Execution Via Node.EXE · test · high · {"category":"process_creation","product":"windows"}
- Node Process Executions · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0172 Behavior-chain, platform-aware detection strategy for T1127 Trusted Developer Utilities Proxy Execution (Windows)
AN0488 Analytic 0488
A trusted/signed developer utility (parent) is executed in a non-developer context and (a) spawns suspicious children (e.g., powershell.exe, cmd.exe, rundll32.exe, regsvr32.exe, wscript.exe), (b) loads unsigned/user-writable DLLs, (c) writes and then runs a new PE from user-writable paths, and/or (d) immediately makes outbound network connections.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- File Creation · DC0039
- Module Load · DC0016
- Network Connection Creation · DC0082
- Process Creation · DC0032
- Process Metadata · DC0034
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.