Skip to content

Hide Navigation Hide TOC

Dynamic CSharp Compile Artefact (e4a74e34-ecde-4aab-b2fb-9112dd01aed0)

When C# is compiled dynamically, a .cmdline file will be created as a part of the process. Certain processes are not typically observed compiling C# code, but can do so without touching disk. This can be used to unpack a payload for execution

Cluster A Galaxy A Cluster B Galaxy B Level
Dynamic CSharp Compile Artefact (e4a74e34-ecde-4aab-b2fb-9112dd01aed0) Sigma-Rules Compile After Delivery - T1027.004 (c726e0a2-a57a-4b7b-a973-d0f013246617) Attack Pattern 1
Obfuscated Files or Information - T1027 (b3d682b6-98f2-4fb0-aa3b-b4df007ca70a) Attack Pattern Compile After Delivery - T1027.004 (c726e0a2-a57a-4b7b-a973-d0f013246617) Attack Pattern 2