Important Detection 2026: MSBuild and Regasm Abuse for Signed Binary Proxy Execution
Detects the execution of legitimate developer utilities msbuild.exe, regasm.exe, and regsvcs.exe in manners consistent with malicious proxy execution. This includes the use of inline tasks in project files, remote network-sourced project files, or specific command-line arguments (such as /codebase or /unregister) that suggest the abuse of these binaries to execute arbitrary code or bypass application control mechanisms, while excluding known legitimate developer-related parent processes and build workflows.
Sigma

