BIOC Informational

MSBuild execution

Attackers may use MSBuild.exe to proxy execution of code through a trusted Windows utility.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Trusted Developer Utilities Proxy Execution: MSBuild (T1127.001)
Indicator:

Process action type = execution AND target process name = msbuild.exe

Preventable: yes