An EDR alert shows a signed Windows process launching from a user’s Downloads folder, using mshta to execute remote JavaScript and later rundll32 to load a DLL. The binaries are legitimate but signed. Which ATT&CK technique best explains this living-off-the-land execution behavior?
Select an answer to reveal the explanation.
Short Explanation
Think of it like using a trusted shop key to open a door you shouldn’t. Signed binaries such as mshta and rundll32 let attackers blend in, so you should map that to System Binary Proxy Execution, not just notice that a script ran.
Full Explanation
Living-off-the-land execution uses trusted operating-system binaries to run attacker code, so the analyst’s job is to classify the behavior rather than the file name. Here, mshta and rundll32 are legitimate signed Windows utilities that can execute remote script or load DLLs, which matches the ATT&CK technique for System Binary Proxy Execution. Masquerading is wrong because it describes making a process appear to be a trusted file or location, not using the real binary’s intended capability. Command and Scripting Interpreter is wrong because it covers abuse of interpreters such as cmd, PowerShell, or bash, while the core issue here is proxy execution through native binaries. Trusted Developer Utilities Proxy Execution is wrong because it refers to build or development tools such as compilers or build utilities, not general signed Windows execution helpers. Exam caveat: ATT&CK may list subtechniques for specific binaries, but the parent technique is the best answer when the stem asks for the broader classification. Operational check: correlate the parent process, command line, network destination, and file origin to confirm the binary is being used to proxy execution rather than performing normal administrative work.