atomic-red-team/Windows/Execution/Trusted_Developer_Utilities.md

13 lines
415 B
Markdown
Raw Permalink Normal View History

2017-10-11 17:35:17 +00:00
## Trusted Developer Utilities
MITRE ATT&CK Technique: [T1127](https://attack.mitre.org/wiki/Technique/T1127)
### MSBuild.exe - [Inline Tasks](https://msdn.microsoft.com/en-us/library/dd722601.aspx)
C:\Windows\Microsoft.Net\Framework\v4.0.30319\MSBuild.exe File.csproj
## Test Script
[MSBuildBypass.csproj](https://github.com/redcanaryco/atomic-red-team/blob/master/Windows/Payloads/MSBuildBypass.csproj)