Rule Info
Name
Suspicious Creation of .NET Binaries or Configs Outside Legitimate Paths
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects creation of .NET framework binaries or configuration files outside of legitimate installation paths.
It might indicate attempts to establish persistence or execute malicious code using the AppDomainManager technique.
In this technique, adversaries may create or modify .NET binaries or configuration files in non-standard locations
to hijack the AppDomainManager, which is responsible for managing application domains in the .NET framework.
This can allow attackers to execute malicious code with elevated privileges or maintain persistence on a compromised system.
Date
2026-07-20 00:00:00
Modified
None
Id
c874755d-c60b-4d9d-9c4e-c799a9959b0f
Tags
attack.stealth attack.execution attack.t1574.014
Type
Nextron Sigma feed only (private)
