Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0556 — Behavior-chain detection strategy for T1127.001 Trusted Developer Utilities Proxy Execution: MSBuild (Windows)
DET0556

Behavior-chain detection strategy for T1127.001 Trusted Developer Utilities Proxy Execution: MSBuild (Windows)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1535 Analytic 1535
Windows

MSBuild.exe is invoked outside expected developer/build contexts or with anomalous arguments (e.g., non-canonical paths, remote shares, Base64/obfuscated property values). Within a short window, it (a) spawns high-risk LOLBins/script interpreters, (b) writes new PE/DLL/script artifacts into user-writable paths and executes them, (c) loads unsigned/user-writable modules, (d) performs memory injection/thread creation into other processes, and/or (e) initiates outbound network connections.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Sysmon EventCode=8 WinEventLog:Sysmon EventCode=10 WinEventLog:Microsoft-Windows-CodeIntegrity/Operational Unsigned/invalid signature modules or images loaded by msbuild.exe or its children EDR:AMSI Malicious inline C#/script blobs embedded in MSBuild projects if intercepted by AMSI-aware loaders (rare but possible via chained LOLBins)
[TimeWindow] Correlation window between msbuild.exe start, payload write, suspicious child spawn, and network (e.g., 0–30 minutes).
[DeveloperHosts] Tag/allowlist known developer or CI/CD hosts to reduce noise.
[SuspiciousChildList] High-risk children (powershell.exe, rundll32.exe, regsvr32.exe, cmd.exe, wscript.exe, mshta.exe) spawned by msbuild.exe.
[RarePathRegex] Regex of user-writable or atypical paths (e.g., %TEMP%, %APPDATA%, OneDrive sync dirs) used to drop payloads.
[UnsignedOrInvalidSignatureOnly] Tighten alerting to cases with invalid or missing signatures on modules/children.
[NetworkReputationThreshold] Minimum rarity/risk score for external destinations to alert.
[BehaviorRiskScoreThreshold] Numeric threshold for fused, scored correlation (e.g., ≥70/100 triggers an alert).

Detected Techniques

1

Details

MITRE ID
DET0556
STIX ID
x-mitre-detection-strategy--5fb0bb0d-cc9c-47aa-86f2-567b4ee642ff
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.