Arbitrary DLL or Csproj Code Execution Via Dotnet.EXE

 Original Source: [Sigma source]
Title: Arbitrary DLL or Csproj Code Execution Via Dotnet.EXE
Status: test
Description:Detects execution of arbitrary DLLs or unsigned code via a ".csproj" files via Dotnet.EXE.
References:
  -https://lolbas-project.github.io/lolbas/OtherMSBinaries/Dotnet/
  -https://twitter.com/_felamos/status/1204705548668555264
  -https://bohops.com/2019/08/19/dotnet-core-a-vector-for-awl-bypass-defense-evasion/
Author: Beyu Denis, oscd.community
Date: 2020-10-18
modified:2025-10-08
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\dotnet.exe' OriginalFileName:'.NET Host'   selection_cli:
    CommandLine|endswith:
      -'.csproj'
      -'.csproj"'
      -'.dll'
      -'.dll"'
      -'.csproj''
      -'.dll''

  filter_optional_notepadplus_plus:
    ParentImage:
      -'C:\Program Files (x86)\Notepad++\notepad++.exe'
      -'C:\Program Files\Notepad++\notepad++.exe'

    CommandLine|contains|all:
      -'C:\ProgramData\CSScriptNpp\'
      -'-cscs_path:'
      -'\cs-script\cscs.dll'

  condition:all of selection_* and not 1 of filter_optional_*
Falsepositives:
  -Legitimate administrator usage
Level: medium