MSBuild: A Profitable Sidekick!
ID: b6b1f548-2f31-509e-9b15-d657ed2db82c
STIX ID: report--b6b1f548-2f31-509e-9b15-d657ed2db82c
Feed Name: TrustedSec blog
Threat Score
This blog post demonstrates using MSBuild.exe (and MSBuild techniques) to compile and execute inline C# payloads from XML files as a living-off-the-land method for post-exploitation on hardened Windows systems; it documents transferring prebuilt GhostPack tools, performing Kerberoast/SPN extraction (Rubeus), running SharpUp and SharpDump to create minidumps, and recovering Domain Admin credentials during an engagement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
