Rule Info
Name
NET Config File Creation by Potentially Suspicious Process
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects .NET configuration files (.exe.config) with potential AppDomainManager hijack patterns
being created by suspicious processes such as scripting engines, downloaders, or interpreters.
Adversaries may use these processes to drop .NET configuration files that hijack the AppDomainManager,
which is responsible for managing application domains in the .NET framework.
Date
2026-07-20 00:00:00
Modified
None
Id
140ac4f2-017f-42e6-9d9a-269d52457307
Tags
attack.stealth attack.execution attack.t1574.014
Type
Nextron Sigma feed only (private)
