Suspicious Application Config File Dropped Beside Trusted .NET Binary for App Domain Manager Injection

PremiumReviewedSigma · Medium · v1
Product
windows
Category
file_event
Author
HuntRule
Published
2026-09-27
Updated
2026-09-27

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects creation of an application configuration file with the .exe.config extension in a user-writable location, the delivery step for App Domain Manager injection where the config redirects a trusted signed .NET binary to load an attacker assembly. The config declares an appDomainManagerAssembly that the runtime honors on startup, executing attacker code under the trusted process. A dropped .exe.config in a temporary or user directory beside a signed binary is a strong hijack indicator.

Related detections9 linkedT1574.001 — drag to rearrange
Malicious DLL Sideload via SentinelBrowserNativeHost
Suspicious version.dll Sideloading via ADExplorer
Suspicious Acrobat.exe Loading Co-located DLL from ProgramData
Suspicious IntelAudioService Execution with StateRepository Arguments via SPECTRALVIPER
Malicious Kazuar DLL Side-Loading via Renamed Host Binaries
Malicious Lazarus DLL Side-Loading via Colorcpl from ProgramData (via process_creation)
Malicious Lazarus DLL Side-Loading via PresentationHost from Non-Standard Path (via process_creation)
Suspicious msvc_4.dll Side-Load from Typosquatted NVIDlA Directory via Image Load
Suspicious DLL Load from WPS INetCache Temp Directory via Image Load
Suspicious Application Config File Dropped Beside Trusted .NET Binary for App Domain Manager Injection
Pivot detection · T1574.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.