ATT&CK 기법 · Stealth
System Binary Proxy Execution T1218
이 기법을 다룬 REVELARE 한국어 위협 분석 5편 · Stealth
이 기법을 다룬 분석
MITRE 공식 정의
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system.(Citation: LOLBAS Project) Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature vali…
플랫폼: Linux, macOS, Windows