{"id":"T1127.001","name":"MSBuild","url":"https://attack.mitre.org/techniques/T1127/001","tactics":["stealth","execution"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0556","stix_id":"x-mitre-detection-strategy--5fb0bb0d-cc9c-47aa-86f2-567b4ee642ff","name":"Behavior-chain detection strategy for T1127.001 Trusted Developer Utilities Proxy Execution: MSBuild (Windows)","url":"https://attack.mitre.org/detectionstrategies/DET0556","analytics":[{"id":"AN1535","stix_id":"x-mitre-analytic--e24b6c08-4fd0-40c7-a71a-762cc08d6085","name":"Analytic 1535","description":"MSBuild.exe is invoked outside expected developer/build contexts or with anomalous arguments (e.g., non-canonical paths, remote shares, Base64/obfuscated property values). Within a short window, it (a) spawns high-risk LOLBins/script interpreters, (b) writes new PE/DLL/script artifacts into user-writable paths and executes them, (c) loads unsigned/user-writable modules, (d) performs memory injection/thread creation into other processes, and/or (e) initiates outbound network connections.","url":"https://attack.mitre.org/detectionstrategies/DET0556#AN1535","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=8","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Microsoft-Windows-CodeIntegrity/Operational","channel":"Unsigned/invalid signature modules or images loaded by msbuild.exe or its children","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"wineventlog-microsoft-windows-codeintegrity-operational"},{"name":"EDR:AMSI","channel":"Malicious inline C#/script blobs embedded in MSBuild projects if intercepted by AMSI-aware loaders (rare but possible via chained LOLBins)","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"edr-amsi"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlation window between msbuild.exe start, payload write, suspicious child spawn, and network (e.g., 0–30 minutes)."},{"field":"DeveloperHosts","description":"Tag/allowlist known developer or CI/CD hosts to reduce noise."},{"field":"SuspiciousChildList","description":"High-risk children (powershell.exe, rundll32.exe, regsvr32.exe, cmd.exe, wscript.exe, mshta.exe) spawned by msbuild.exe."},{"field":"RarePathRegex","description":"Regex of user-writable or atypical paths (e.g., %TEMP%, %APPDATA%, OneDrive sync dirs) used to drop payloads."},{"field":"UnsignedOrInvalidSignatureOnly","description":"Tighten alerting to cases with invalid or missing signatures on modules/children."},{"field":"NetworkReputationThreshold","description":"Minimum rarity/risk score for external destinations to alert."},{"field":"BehaviorRiskScoreThreshold","description":"Numeric threshold for fused, scored correlation (e.g., ≥70/100 triggers an alert)."}],"live":true,"detection_strategies":["DET0556"],"techniques":["T1127.001"]}],"live":true,"version":"1.0","techniques":["T1127.001"]}],"sigma_rules":[{"id":"50e54b8d-ad73-43f8-96a1-5191685b17a4","title":"Silenttrinity Stager Msbuild Activity","author":"Kiran kumar s, oscd.community","status":"test","level":"high","date":"2020-10-11","modified":"2022-10-05","description":"Detects a possible remote connections to Silenttrinity c2","references":["https://www.blackhillsinfosec.com/my-first-joyride-with-silenttrinity/"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.execution","attack.stealth","attack.t1127.001"],"path":"rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml","techniques":["T1127.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}