NET Config File Creation in Suspicious Location

Rule Info

Name
NET Config File Creation in Suspicious Location
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects .NET configuration files (.exe.config) with potential AppDomainManager hijack patterns being created in suspicious or non-standard locations. Adversaries may create or modify .NET configuration files in non-standard locations to hijack the AppDomainManager, which is responsible for managing application domains in the .NET framework.
Date
2026-07-20 00:00:00
Modified
None
Id
9456a34d-0f28-41ec-a92e-d222fb2cfbb1
Tags
attack.stealth attack.execution attack.t1574.014
Type
Nextron Sigma feed only (private)

Rule History