MSBuild
Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio. It handles XML formatted project files that define requirements for loading and building various platforms and configurations.(Citation: MSDN MSBuild) Adversaries can abuse MSBuild to proxy execution of malicious code. The inline task capability of MSBuild that was introduced in .NET version 4 allows for C# or Visual B...
BY SOURCE
PROCEDURES (13)
Auto-extracted: 3 detections for network connection monitoring
Auto-extracted: 2 detections for unusual
Auto-extracted: 2 detections for c2
Auto-extracted: 2 detections for script execution monitoring
Auto-extracted: 1 detections for wmi
Auto-extracted: 1 detections for general monitoring
Auto-extracted: 1 detections for module load monitoring
Auto-extracted: 1 detections for process creation monitoring
Auto-extracted: 1 detections for wmi
Auto-extracted: 1 detections for unusual
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for command line monitoring