Compliance Node Overview
MITRE ATT&CK T1216 (System Script Proxy Execution) is an Enterprise Defense Evasion technique. Adversaries may use trusted scripts, often signed with certificates, to proxy the execution of malicious files. Several Microsoft signed scripts that have been downloaded from Microsoft or are default on Windows installations can be used to proxy execution of other files. This behavior may be abused by adversaries to execute malicious files that could bypass application control and signature validation on systems. ATT&CK documents 2 sub-techniques: T1216.001 PubPrn; T1216.002 SyncAppvPublishingServer. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-02, CM-06, CM-07, SI-04, SI-07, SI-10.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1216/
SHA-256 integrity: fd5eb82721bb8f7c9d0cf4af9a8b321150642eb6c42285805bc82cc0e30b24e2
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1216: System Script Proxy Execution (https://attack.mitre.org/techniques/T1216/) with 2 sub-techniques
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.