Suspicious App Domain Manager Injection via Environment Variables

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-30
Updated
2026-09-30

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects processes started with the APPDOMAIN_MANAGER_ASM or APPDOMAIN_MANAGER_TYPE environment variables set, the environment-driven form of App Domain Manager injection that forces a .NET runtime to load an attacker-specified assembly at startup. These variables are honored by the CLR to override the default app domain manager, hijacking execution inside a trusted signed binary. Their presence in a process environment is highly abnormal and indicates deliberate .NET execution hijacking.

Related detections9 linkedT1574.001 — drag to rearrange
Malicious DtlCrashCatch DLL Side-Loading via OneDrive Sync Service by SPECTRALVIPER
Malicious PlugX DLL Sideloading via Canon cnmpaui Utility (via image_load)
Suspicious DLL Sideloading via FMAPP Executable from Non-Standard Path via process_creation
Suspicious Svchost Execution from Non-System Path
Suspicious Svchost Execution from Non-Services Parent
Suspicious jli.dll Sideloading by Non-Java Trusted Binary
Malicious DLL Sideload via SentinelBrowserNativeHost
Suspicious version.dll Sideloading via ADExplorer
Suspicious Application Config File Dropped Beside Trusted .NET Binary for App Domain Manager Injection
Suspicious App Domain Manager Injection via Environment Variables
Pivot detection · T1574.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.