Detection of Native .NET Binaries Executing from Non-Standard Paths
Adversaries move native Windows .NET binaries to unconventional directories to bypass security controls and facilitate malicious code execution or persistence.
Adversaries frequently employ masquerading techniques to evade detection by moving legitimate native .NET binaries, such as InstallUtil or similar system utilities, to non-standard, unconventional directories on Windows systems. By executing these binaries from locations outside of trusted paths like C:\Windows\System32, C:\Windows\SysWOW64, or C:\Windows\WinSxS, attackers attempt to blend in with legitimate activity while establishing persistence, escalating privileges, or executing arbitrary malicious code. This technique is specifically linked to masquerading system utilities (T1036.003) and proxy execution (T1218.004) to hide execution flows from standard security monitoring. This behavior has been observed in various destructive malware campaigns, including operations like WhisperGate. Detecting these deviations requires monitoring EDR telemetry for process executions where the file name matches a known .NET binary but the path does not align with expected system structures.
Impact
Successful execution of .NET binaries from non-standard locations allows attackers to bypass baseline security restrictions, potentially leading to unauthorized data destruction, system compromise, or long-term persistence in the target environment. This activity is often a precursor to more severe impacts, including ransomware deployment or the exfiltration of sensitive information.
Recommendation
Prioritize the implementation of EDR-based detection logic to identify .NET binaries running from suspicious locations.
- Enable process creation monitoring (Sysmon Event ID 1 or Security Event 4688) to capture the required process path, process name, and original file name metadata.
- Deploy the provided Sigma rule to SIEM environments to alert on unauthorized execution paths for identified .NET binaries.
- Review and tune existing whitelist policies to ensure that third-party applications do not trigger false positives when executing legitimately from custom installation directories.
Immediate actions
Deploy the .NET non-standard path detection rule and tune against known benign third-party software in the environment.
Threat Hunt
Search for non-standard process paths involving common .NET binaries (e.g., InstallUtil.exe, csc.exe).
Data: Process creation logs with full path information.
Mitigations
Enforce strict application execution policies and utilize AppLocker or WDAC to restrict execution of binaries from user-writable directories.
T1036.003
Detection coverage 1
Detect .NET Binary Execution from Non-Standard Paths
mediumDetects the execution of known native .NET binaries from directories outside of standard Windows system paths, which may indicate masquerading or evasion.
Detection queries are available on the platform. Get full rules →