Use of Scriptrunner.exe (64760eef-87f7-4ed3-93fd-655668ea9420)
The "ScriptRunner.exe" binary can be abused to proxy execution through it and bypass possible whitelisting
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) | Attack Pattern | Use of Scriptrunner.exe (64760eef-87f7-4ed3-93fd-655668ea9420) | Sigma-Rules | 1 |