Hunting .Net Malware
To hunt for msbuild execution, focus on Sysmon logs where the image of the process contains "msbuild.exe". Msbuild is being used by attackers to compile and execute code (https://lolbas-project.github
Task 1. Has msbuild executed malware on the machine?
Get-WinEvent -FilterHashtable @{logname="Microsoft-Windows-Sysmon/Operational"; id=1} | Where-Object {$_.Properties[4].Value -like "*msbuild*"} | fl

Task 2. What was the initial stager?

Task 3. How was the malware downloaded? Why did the attacker choose this method?



Task 4. What was the attacker's IP and Port?



Last updated