For the complete documentation index, see llms.txt. This page is also available as Markdown.

Uncommon DotNet module load relationship

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Reflective Code Loading (T1620)

Severity

Informational

Description

A signed process that usually doesn't use DotNet loaded a common DotNet module.

Attacker's Goals

Adversaries may reflectively load DotNet code into a process to conceal execution of malicious payloads.

Investigative actions

  • Investigate the actor process for potential malicious activity.

  • Check for recently installed services that may load DotNet modules.

Was this helpful?