New Tool Release: NPS_Payload
ID: aa380843-2297-53dc-9fb9-d4ebcb207bf2
STIX ID: report--aa380843-2297-53dc-9fb9-d4ebcb207bf2
Feed Name: TrustedSec blog
Threat Score
This report documents a technique and tool (nps_payload) that injects encoded PowerShell into an msbuild-compatible XML/CSProj file to achieve code execution via msbuild.exe, including deployment via local copy or UNC share, notes that execution avoids powershell.exe and can evade Event ID 4688, and provides detection guidance and a link to the TrustedSec GitHub repository.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
