Non-MSBuild developer utility spawns a script interpreter
AN0488's parent-child leg, scoped to the trusted developer utilities the technique's own citations name that are not MSBuild: the DNX execution environment and the Roslyn C# interactive REPL (both cited via the "DNX Bypass" and "RCSI Bypass" references), the WinDbg console debugger, the .NET CLI, IL assembler and MSBuild's separate file-tracking helper. MSBuild itself is deliberately excluded — it is the published T1127.001 sibling — so this rule and that one alert on disjoint ParentImage sets even though both match the same SuspiciousChildList shape MITRE gives in AN0488. The payload-write, unsigned-module-load and network-egress legs of the analytic are separate events with no join Sigma can express, so only the immediate child-spawn is checked; a utility that shells out after a delay, or that loads a malicious DLL without ever spawning a child process at all, will not match. Note the process source is Security 4688, which needs Audit Process Creation enabled and returns nothing at all without it. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0172, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full descriptionShow less
The detection
The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.
detection.yml
title: Non-MSBuild developer utility spawns a script interpreterid: ebcf6dba-b49f-4ea0-a046-155f76b898ffstatus: experimentaldescription: | AN0488's parent-child leg, scoped to the trusted developer utilities the technique's own citations name that are not MSBuild: the DNX execution environment and the Roslyn C# interactive REPL (both cited via the "DNX Bypass" and "RCSI Bypass" references), the WinDbg console debugger, the .NET CLI, IL assembler and MSBuild's separate file-tracking helper. MSBuild itself is deliberately excluded — it is the published T1127.001 sibling — so this rule and that one alert on disjoint ParentImage sets even though both match the same SuspiciousChildList shape MITRE gives in AN0488. The payload-write, unsigned-module-load and network-egress legs of the analytic are separate events with no join Sigma can express, so only the immediate child-spawn is checked; a utility that shells out after a delay, or that loads a malicious DLL without ever spawning a child process at all, will not match. Note the process source is Security 4688, which needs Audit Process Creation enabled and returns nothing at all without it. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0172, not hand-written and not tested by its author. Any lab result is on this rule's own page.references: - https://attack.mitre.org/techniques/T1127 - https://attack.mitre.org/detectionstrategies/DET0172author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags: - attack.defense-evasion - attack.execution - attack.t1127logsource: category: process_creation product: windowsdetection: selection_parent: ParentImage|endswith: - '\dnx.exe' - '\rcsi.exe' - '\csi.exe' - '\cdb.exe' - '\windbg.exe' - '\dotnet.exe' - '\ilasm.exe' - '\Tracker.exe' selection_child: Image|endswith: - '\powershell.exe' - '\pwsh.exe' - '\cmd.exe' - '\wscript.exe' - '\cscript.exe' - '\mshta.exe' - '\rundll32.exe' - '\regsvr32.exe' - '\certutil.exe' condition: selection_parent and selection_childfalsepositives: - "dotnet.exe build and test pipelines on developer workstations and CI agents, where dotnet build/test/publish or a custom MSBuild target invoked through the dotnet CLI shells out to cmd.exe or powershell.exe for pre/post-build steps — this is the single highest-volume match this rule will produce, which is why the level below is not set higher." - "Reverse-engineering and debugging workstations where cdb.exe or windbg.exe is used interactively and its scripting extensions launch a helper process as part of routine analysis work, indistinguishable on this logic alone from a debugger being used to proxy execution." - "csi.exe (Roslyn C# Interactive) invoked from a build or notebook-style workflow that shells out to run a generated script, on hosts where interactive C# scripting is a normal developer tool rather than an anomaly."level: mediumSentinel · KQL
Run this as a search.
DeviceProcessEvents| where ((InitiatingProcessFolderPath endswith "\\dnx.exe" or InitiatingProcessFolderPath endswith "\\rcsi.exe" or InitiatingProcessFolderPath endswith "\\csi.exe" or InitiatingProcessFolderPath endswith "\\cdb.exe" or InitiatingProcessFolderPath endswith "\\windbg.exe" or InitiatingProcessFolderPath endswith "\\dotnet.exe" or InitiatingProcessFolderPath endswith "\\ilasm.exe" or InitiatingProcessFolderPath endswith "\\Tracker.exe") and (FolderPath endswith "\\powershell.exe" or FolderPath endswith "\\pwsh.exe" or FolderPath endswith "\\cmd.exe" or FolderPath endswith "\\wscript.exe" or FolderPath endswith "\\cscript.exe" or FolderPath endswith "\\mshta.exe" or FolderPath endswith "\\rundll32.exe" or FolderPath endswith "\\regsvr32.exe" or FolderPath endswith "\\certutil.exe"))
Splunk · SPL
Run this as a search.
index=* ((ParentImage="*\\dnx.exe" OR ParentImage="*\\rcsi.exe" OR ParentImage="*\\csi.exe" OR ParentImage="*\\cdb.exe" OR ParentImage="*\\windbg.exe" OR ParentImage="*\\dotnet.exe" OR ParentImage="*\\ilasm.exe" OR ParentImage="*\\Tracker.exe") AND (Image="*\\powershell.exe" OR Image="*\\pwsh.exe" OR Image="*\\cmd.exe" OR Image="*\\wscript.exe" OR Image="*\\cscript.exe" OR Image="*\\mshta.exe" OR Image="*\\rundll32.exe" OR Image="*\\regsvr32.exe" OR Image="*\\certutil.exe"))Elastic · ES|QL
Run this as a search.
FROM logs-*| WHERE ((TO_LOWER(process.parent.executable) LIKE "*\\\\dnx.exe" OR TO_LOWER(process.parent.executable) LIKE "*\\\\rcsi.exe" OR TO_LOWER(process.parent.executable) LIKE "*\\\\csi.exe" OR TO_LOWER(process.parent.executable) LIKE "*\\\\cdb.exe" OR TO_LOWER(process.parent.executable) LIKE "*\\\\windbg.exe" OR TO_LOWER(process.parent.executable) LIKE "*\\\\dotnet.exe" OR TO_LOWER(process.parent.executable) LIKE "*\\\\ilasm.exe" OR TO_LOWER(process.parent.executable) LIKE "*\\\\tracker.exe") AND (TO_LOWER(process.executable) LIKE "*\\\\powershell.exe" OR TO_LOWER(process.executable) LIKE "*\\\\pwsh.exe" OR TO_LOWER(process.executable) LIKE "*\\\\cmd.exe" OR TO_LOWER(process.executable) LIKE "*\\\\wscript.exe" OR TO_LOWER(process.executable) LIKE "*\\\\cscript.exe" OR TO_LOWER(process.executable) LIKE "*\\\\mshta.exe" OR TO_LOWER(process.executable) LIKE "*\\\\rundll32.exe" OR TO_LOWER(process.executable) LIKE "*\\\\regsvr32.exe" OR TO_LOWER(process.executable) LIKE "*\\\\certutil.exe"))
Wazuh · XML rule
Deploy to your manager — this is a rule, not a search.
<group name="sigma,windows,process_creation,"> <!-- Rule ids must be unique on your manager; 100000+ is the user range. --> <rule id="100000" level="7"> <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. --> <field name="ParentImage" type="pcre2">(?i)(\\dnx\.exe$|\\rcsi\.exe$|\\csi\.exe$|\\cdb\.exe$|\\windbg\.exe$|\\dotnet\.exe$|\\ilasm\.exe$|\\Tracker\.exe$)</field> <field name="Image" type="pcre2">(?i)(\\powershell\.exe$|\\pwsh\.exe$|\\cmd\.exe$|\\wscript\.exe$|\\cscript\.exe$|\\mshta\.exe$|\\rundll32\.exe$|\\regsvr32\.exe$|\\certutil\.exe$)</field> <description>Non-MSBuild developer utility spawns a script interpreter</description> <mitre> <id>T1127</id> </mitre> </rule></group>
Verdicts · reactions · comments
Community
Verdicts from engineers who actually deployed it, and the conversation around it.
Nobody has run this in a real environment and said what happened.
Verdicts from engineers who deployed it
0 castNo verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.
Log in to report a verdict.
Log in to join the discussion.
No comments yet. Someone who deploys this will have something to say about it.