AppDomainManager Environment Variable Hijack

Rule Info

Name
AppDomainManager Environment Variable Hijack
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the use of environment variables related to the .NET AppDomainManager, which can be hijacked by adversaries to execute malicious code within trusted processes. Adversaries can set these variables to point to a malicious assembly, forcing legitimate .NET applications to load it upon startup. This technique allows for stealthy code execution within trusted, signed processes.
Date
2026-07-20 00:00:00
Modified
None
Id
51dde833-031d-4784-8ba7-2e2425ee80d0
Tags
attack.stealth attack.execution attack.t1574.014
Type
Nextron Sigma feed only (private)

Rule History