1200KM / simulation
T1218 System Binary Proxy Execution — Attack Simulation
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature…
Technique description
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- DiskShadow Command Execution
Procedure 0e1483ba-8f0c-425d-b8c6-42736e058eaa; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Lolbas ie4uinit.exe use as proxy
Procedure 13c0804e-615e-43ad-b223-2dfbacd0b0b3; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Load Arbitrary DLL via Wuauclt (Windows Update Client)
Procedure 49fbd548-49e9-4bb7-94a6-3769613912b8; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Renamed Microsoft.Workflow.Compiler.exe Payload Executions
Procedure 4cc40fd7-87b8-4b16-b2d7-57534b86b911; elevation not declared required; cleanup not declared. Not executed or individually validated.
- InfDefaultInstall.exe .inf Execution
Procedure 54ad7d5a-a1b5-472c-b6c4-f8090fb2daef; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Lolbin Gpscript logon option
Procedure 5bcda9cd-8e85-48fa-861d-b5a85d91d48c; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Binary Proxy Execution - Wlrmdr Lolbin
Procedure 7816c252-b728-4ea6-a683-bd9441ca0b71; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Microsoft.Workflow.Compiler.exe Payload Execution
Procedure 7cbb0f26-a4c1-4f77-b180-a009aa05637e; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Invoke-ATHRemoteFXvGPUDisablementCommand base test
Procedure 9ebe7901-7edf-45c0-b5c7-8366300919db; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Provlaunch.exe Executes Arbitrary Command via Registry Key
Procedure ab76e34f-28bf-441f-a39c-8db4835b89cc; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Register-CimProvider - Execute evil dll
Procedure ad2c17ed-f626-4061-b21e-b9804a6f3655; elevation not declared required; cleanup not declared. Not executed or individually validated.
- LOLBAS CustomShellHost to Spawn Process
Procedure b1eeb683-90bb-4365-bbc2-2689015782fe; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- mavinject - Inject DLL into running process
Procedure c426dacf-575d-4937-8611-a148a86a5e61; elevation required; cleanup not declared. Not executed or individually validated.
- ProtocolHandler.exe Downloaded a Suspicious File
Procedure db020456-125b-4c8b-a4a7-487df8afb5a2; elevation not declared required; cleanup not declared. Not executed or individually validated.
- LOLBAS Msedge to Spawn Process
Procedure e5eedaed-ad42-4c1e-8783-19529738a349; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Lolbin Gpscript startup option
Procedure f8da74bb-21b8-4af9-8d84-f2c8e4a220e3; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.