1200KM / simulation
T1127.001 MSBuild — Attack Simulation
Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio. It handles XML formatted project files that define requirements for loading and building various platforms and configurations. Adversaries can abuse MSBuild to proxy execution of malicious code. The inline task capability of MSBuild that was introduced in .NET version 4…
Technique description
Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio. It handles XML formatted project files that define requirements for loading and building various platforms and configurations. Adversaries can abuse MSBuild to proxy execution of malicious code. The inline task capability of MSBuild that was introduced in .NET version 4…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- MSBuild Bypass Using Inline Tasks (C#)
Procedure 58742c0f-cb01-44cd-a60b-fb26e8871c93; elevation not declared required; cleanup not declared. Not executed or individually validated.
- MSBuild Bypass Using Inline Tasks (VB)
Procedure ab042179-c0c5-402f-9bc8-42741f5ce359; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.