Suspicious MSBuild Execution Spawned by Command Shell for Process Hollowing (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-11
Updated
2026-10-11

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects MSBuild.exe launched by a command shell or PowerShell without a project or solution file on the command line, an anomaly consistent with the process hollowing target abused by HijackLoader to run AsyncRAT. Genuine MSBuild builds reference a project, solution, or response file.

Related detections9 linkedT1055.012 — drag to rearrange
Malicious Desktop Window Manager Impersonation From Non-System Path via process_creation
Suspicious MSBuild Execution of Inline Payload (via process_creation)
Suspicious MSBuild Execution as LOLBin from User-Writable Path (via process_creation)
Suspicious Local XML Compilation via MSBuild
Malicious Winlogon Shell Hijack Loading MSBuild
Suspicious .NET Utility Spawned by AutoHotkey Loader for Process Hollowing (via process_creation)
Suspicious csc.exe Spawned by Document Reader for Process Injection
Suspicious RegAsm Execution Spawned by Script Host for Process Hollowing (via process_creation)
Suspicious .NET Utility Launched as Process Injection Target (via process_creation)
Suspicious MSBuild Execution Spawned by Command Shell for Process Hollowing (via process_creation)
Pivot detection · T1055.012 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.