T1027.004 Compile After Delivery
Sub-technique of T1027 Obfuscated Files or Information
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code. Text-based source code files may subvert analysis and scrutiny from protections targeting executables/binaries. These payloads will need to be compiled before execution; typically via native utilities such as ilasm.exe(Citation: ATTACK IQ), csc.exe, or…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Csc.EXE Execution Form Potentially Suspicious Parenthightest · windows
- Visual Basic Command Line Compiler Usagehightest · windows
- Dynamic .NET Compilation Via Csc.EXEmediumtest · windows
- Potential Application Whitelisting Bypass via Dnx.EXEmediumtest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.