AppDomainManager Injection via Environment Variables

Rule Info

Name
AppDomainManager Injection via Environment Variables
Author
Max Altgelt
Description
Detects environment variables that indicate injection of AppDomainManager DLLs into .NET binaries
Date
2024-08-28 00:00:00
Modified
None
Id
0cbaf03f-d0cf-4d53-b8ee-7df21a1789f4
Tags
attack.defense-evasion attack.t1055
Type
Nextron Sigma feed only (private)

Rule History