{"id":"T1574.012","name":"COR_PROFILER","url":"https://attack.mitre.org/techniques/T1574/012","tactics":["stealth","execution"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0479","stix_id":"x-mitre-detection-strategy--8276f61b-0147-4e72-94fb-7cdd47dc60ec","name":"Detection Strategy for Hijack Execution Flow using the Windows COR_PROFILER.","url":"https://attack.mitre.org/detectionstrategies/DET0479","analytics":[{"id":"AN1319","stix_id":"x-mitre-analytic--39d115fc-5e7b-423f-94da-a3b4242e07b8","name":"Analytic 1319","description":"Modification of COR_PROFILER-related environment variables or Registry keys (COR_ENABLE_PROFILING, COR_PROFILER, COR_PROFILER_PATH), combined with anomalous .NET process creation or unmanaged DLL loads. Defender observes registry modifications, suspicious process creation with altered environment variables, and profiler DLLs loaded unexpectedly into .NET CLR processes.","url":"https://attack.mitre.org/detectionstrategies/DET0479#AN1319","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AllowedProfilers","description":"List of known good COR_PROFILER CLSIDs and DLLs expected in developer or monitoring environments."},{"field":"ProcessScope","description":"Processes expected to load COR_PROFILER (e.g., Visual Studio) for baseline comparison."},{"field":"TimeWindow","description":"Interval between registry modification or file creation and profiler DLL load into .NET processes."},{"field":"ProfilerDllPaths","description":"Directories considered legitimate for profiler DLLs; deviations should raise alerts."}],"live":true,"detection_strategies":["DET0479"],"techniques":["T1574.012"]}],"live":true,"version":"1.0","techniques":["T1574.012"]}],"sigma_rules":[{"id":"23590215-4702-4a70-8805-8dc9e58314a2","title":"Registry-Free Process Scope COR_PROFILER","author":"frack113","status":"test","level":"medium","date":"2021-12-30","modified":null,"description":"Adversaries may leverage the COR_PROFILER environment variable to hijack the execution flow of programs that load the .NET CLR.\nThe COR_PROFILER is a .NET Framework feature which allows developers to specify an unmanaged (or external of .NET) profiling DLL to be loaded into each .NET process that loads the Common Language Runtime (CLR).\nThese profiliers are designed to monitor, troubleshoot, and debug managed code executed by the .NET CLR.\n(Citation: Microsoft Profiling Mar 2017)\n(Citation: Microsoft COR_PROFILER Feb 2013)\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1574.012/T1574.012.md#atomic-test-3---registry-free-process-scope-cor_profiler"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1574.012"],"path":"rules/windows/powershell/powershell_script/posh_ps_cor_profiler.yml","techniques":["T1574.012"],"cves":[]},{"id":"ad89044a-8f49-4673-9a55-cbd88a1b374f","title":"Enabling COR Profiler Environment Variables","author":"Jose Rodriguez (@Cyb3rPandaH), OTR (Open Threat Research), Jimmy Bayne (@bohops)","status":"test","level":"medium","date":"2020-09-10","modified":"2023-11-24","description":"Detects .NET Framework CLR and .NET Core CLR \"cor_enable_profiling\" and \"cor_profiler\" variables being set and configured.","references":["https://twitter.com/jamieantisocial/status/1304520651248668673","https://www.slideshare.net/JamieWilliams130/started-from-the-bottom-exploiting-data-sources-to-uncover-attck-behaviors","https://www.sans.org/cyber-security-summit/archives","https://learn.microsoft.com/en-us/dotnet/core/runtime-config/debugging-profiling"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.privilege-escalation","attack.execution","attack.stealth","attack.t1574.012"],"path":"rules/windows/registry/registry_set/registry_set_enabling_cor_profiler_env_variables.yml","techniques":["T1574.012"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}