T1127.001 - MSBuild

Sub-technique
Tattiche:
Defense Evasion
Piattaforme:
Windows
Rilevamento:
Not specified
Description:
Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio. It handles XML formatted project files that define requirements for loading and building various platforms and configurations.(Citation: MSDN MSBuild)

Adversaries can abuse MSBuild to proxy execution of malicious code. The inline task capability of MSBuild that was introduced in .NET version 4 allows for C# or Visual Basic code to be inserted into an XML project file.(Citation: MSDN MSBuild)(Citation: Microsoft MSBuild Inline Tasks 2017) MSBuild will compile and execute the inline task. MSBuild.exe is a signed Microsoft binary, so when it is used this way it can execute arbitrary code and bypass application control defenses that are configured to allow MSBuild.exe execution.(Citation: LOLBAS Msbuild)
Metadata
MITRE ID: T1127.001
STIX ID: attack-pattern--c92e3d68-2349-...
Piattaforme: Windows
Created: 13/01/2026 17:48
Updated: 14/03/2026 04:00