name: Suspicious MSBuild Spawn id: a115fba6-5514-11eb-ae93-0242ac130002 version: 2 date: '2021-01-12' author: Michael Haag, Splunk status: production type: TTP description: The following analytic identifies wmiprvse.exe spawning msbuild.exe. This behavior is indicative of a COM object being utilized to spawn msbuild from wmiprvse.exe. It is common for MSBuild.exe to be spawned from devenv.exe while using Visual Studio. In this instance, there will be command line arguments and file paths. In a malicious instance, MSBuild.exe will spawn from non-standard processes and have no command line arguments. For example, MSBuild.exe spawning from explorer.exe, powershell.exe is far less common and should be investigated. data_source: - Sysmon Event ID 1 search: selection1: ParentImage: wmiprvse.exe selection2: OriginalFileName: MSBuild.exe selection3: Image|endswith: msbuild.exe condition: selection1 and selection2 and selection3 how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. known_false_positives: Although unlikely, some legitimate applications may exhibit this behavior, triggering a false positive. references: - https://lolbas-project.github.io/lolbas/Binaries/Msbuild/ - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md tags: analytic_story: - Trusted Developer Utilities Proxy Execution MSBuild - Living Off The Land asset_type: Endpoint confidence: 60 impact: 70 message: Suspicious msbuild.exe process executed on $dest$ by $user$ mitre_attack_id: - T1127 - T1127.001 observable: - name: dest type: Endpoint role: - Victim - name: User type: User role: - Victim product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud risk_score: 42 security_domain: endpoint tests: - name: True Positive Test attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog update_timestamp: true