AppDomainManager Environment Variable Hijack - PsScript

Rule Info

Name
AppDomainManager Environment Variable Hijack - PsScript
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the usage of environment variables related to the .NET AppDomainManager within PowerShell scripts. The presence of these variables in script content may indicate attempts to hijack the AppDomainManager, allowing adversaries to execute malicious code within trusted processes. Setting these variables in scripts can force legitimate .NET applications to load attacker-controlled assemblies, enabling stealthy code execution and persistence.
Date
2026-07-20 00:00:00
Modified
None
Id
3c5fb291-c6f9-4cb6-9836-e78e596eff5c
Tags
attack.stealth attack.execution attack.t1574.014
Type
Nextron Sigma feed only (private)

Rule History