Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0172 — Behavior-chain, platform-aware detection strategy for T1127 Trusted Developer Utilities Proxy Execution (Windows)
DET0172

Behavior-chain, platform-aware detection strategy for T1127 Trusted Developer Utilities Proxy Execution (Windows)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0488 Analytic 0488
Windows

A trusted/signed developer utility (parent) is executed in a non-developer context and (a) spawns suspicious children (e.g., powershell.exe, cmd.exe, rundll32.exe, regsvr32.exe, wscript.exe), (b) loads unsigned/user-writable DLLs, (c) writes and then runs a new PE from user-writable paths, and/or (d) immediately makes outbound network connections.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:AppLocker AppLocker audit/blocks showing developer utilities executing scripts/binaries outside policy
[TimeWindow] Correlation window between developer utility execution, payload write, and network egress (e.g., 0–30 minutes).
[AllowedUtilitiesList] Org-specific list of dev utilities legitimately used on build/dev hosts to suppress noise.
[DeveloperHosts] List of known developer/build systems where these tools are expected; raise severity off-host.
[SuspiciousChildList] Child processes considered high-risk when spawned by dev utilities (powershell.exe, rundll32.exe, regsvr32.exe, cmd.exe, wscript.exe, mshta.exe).
[RarePathRegex] Regex of user-writable or atypical paths (e.g., %TEMP%, %APPDATA%, recycle bin, public profile) for payload drops.
[UnsignedOrInvalidSignatureOnly] Toggle to alert only when child/payload is unsigned or signature invalid to reduce noise.
[ParentProcessAllowList] Known orchestrators (e.g., CI/CD agents) that often run these utilities legitimately.
[NetworkReputationThreshold] Heuristic for rare/unknown destination (no DNS reputation, new domain, geo outside region).

Detected Techniques

1

Details

MITRE ID
DET0172
STIX ID
x-mitre-detection-strategy--f47cb8dc-2120-4541-9306-95053218ba8a
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.