Windows msbuild.exe Network Connections to Ports 80/443

Alerts on initiated outbound 80/443 connections from msbuild.exe on Windows.

FreeReviewedSigma · High · v2
Product
windows
Category
network_connection
Author
Kiran kumar s, oscd.community (SigmaHQ), DRL 1.1
Published
2020-10-11
Updated
2026-07-31

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

Identifies instances where msbuild.exe initiates outbound network connections to destination ports 80 or 443. Attackers may abuse msbuild to download or stage additional components using common web ports, blending into normal outbound traffic. Telemetry relies on process/network connection events that include the connecting image path, destination port, and whether the connection was initiated by the host.

Related detections7 linkedT1127.001 — drag to rearrange
Proxy Execution via MSBuild Running Inline Task XML
MSBuild Executing Non-Project File or Remote Payload
Antivirus Check and Remote Loader Retrieval in LNK Command Chain
Suspicious MSBuild Execution From Office or Archive Extraction Context (via process_creation)
Suspicious MSBuild Execution from Writable Directory (via process_creation)
In-Memory MSBuild Proxy Execution of a Project From a User-Writable Path (via process_creation)
Suspicious MSBuild LOLBin Spawning Script Interpreter (via process_creation)
Windows msbuild.exe Network Connections to Ports 80/443
Pivot detection · T1127.001 · 7 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.