logo

MSBuild: A Profitable Sidekick!

ID: b6b1f548-2f31-509e-9b15-d657ed2db82c

STIX ID: report--b6b1f548-2f31-509e-9b15-d657ed2db82c

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This blog post demonstrates using MSBuild.exe (and MSBuild techniques) to compile and execute inline C# payloads from XML files as a living-off-the-land method for post-exploitation on hardened Windows systems; it documents transferring prebuilt GhostPack tools, performing Kerberoast/SPN extraction (Rubeus), running SharpUp and SharpDump to create minidumps, and recovering Domain Admin credentials during an engagement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.