logo

Hunting For In-Memory .NET Attacks

ID: 99159a11-cd9d-56bd-9bd5-404358184350

STIX ID: report--99159a11-cd9d-56bd-9bd5-404358184350

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2022-06-21

Date Updated: 2026-04-27

...
...

This blog post examines the growing use of .NET in-memory techniques—particularly Assembly.Load(byte[])—by adversaries to evade detection, citing real-world examples (DEEP PANDA, OilRig) and red-team tools; it explains why .NET is attractive to attackers, demonstrates how these techniques enable diskless payloads and application-whitelisting bypasses, and presents detection strategies including an on-demand PowerShell hunting script (Get-ClrReflection) and an eventing proof-of-concept (ClrGuard) to monitor and block CLR loading activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.