{
  "node_id": "mitre-attack-t1216-system-script-proxy-execution",
  "title": "MITRE ATT&CK T1216: System Script Proxy Execution (Enterprise Tactic TA0005 - Defense Evasion)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1216 (System Script Proxy Execution) is an Enterprise Defense Evasion technique. Adversaries may use trusted scripts, often signed with certificates, to proxy the execution of malicious files. Several Microsoft signed scripts that have been downloaded from Microsoft or are default on Windows installations can be used to proxy execution of other files. This behavior may be abused by adversaries to execute malicious files that could bypass application control and signature validation on systems. ATT&CK documents 2 sub-techniques: T1216.001 PubPrn; T1216.002 SyncAppvPublishingServer. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-02, CM-06, CM-07, SI-04, SI-07, SI-10.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-framework-v14"
  ],
  "primary_citations_count": 7
}