Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0466 — Detection of Script-Based Proxy Execution via Signed Microsoft Utilities
DET0466

Detection of Script-Based Proxy Execution via Signed Microsoft Utilities

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1288 Analytic 1288
Windows

Execution of Microsoft-signed scripts (e.g., pubprn.vbs, installutil.exe, wscript.exe, cscript.exe) used to proxy execution of untrusted or external binaries. Behavior is detected through command-line process lineage, child process spawning, and unsigned payload execution from signed parent.

WinEventLog:Sysmon EventCode=1 WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=11
[ParentProcessName] Environment-specific paths to script interpreters like wscript.exe, cscript.exe, pubprn.vbs, or installutil.exe.
[TimeWindow] Time delta between signed script execution and suspicious child process creation.
[ChildCommandLineRegex] Regex pattern used to detect malicious payload execution (e.g., download cradle, PowerShell decode).
[SignedToUnsignedTransition] Indicates whether the parent is signed by Microsoft but child is unsigned or unknown.

Detected Techniques

1

Details

MITRE ID
DET0466
STIX ID
x-mitre-detection-strategy--8ac2b0d0-a589-4c72-9287-a7d9e47065a9
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.