Official Description

Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio. It handles XML formatted project files that define requirements for loading and building various platforms and configurations.(Citation: MSDN MSBuild)

Adversaries can abuse MSBuild to proxy execution of malicious code. The inline task capability of MSBuild that was introduced in .NET version 4 allows for C# or Visual Basic code to be inserted into an XML project file.(Citation: MSDN MSBuild)(Citation: Microsoft MSBuild Inline Tasks 2017) MSBuild will compile and execute the inline task. MSBuild.exe is a signed Microsoft binary, so when it is used this way it can execute arbitrary code and bypass application control defenses that are configured to allow MSBuild.exe execution.(Citation: LOLBAS Msbuild)
Tactics
Stealth, Execution
Platforms
Windows
Parent Technique
T1127 · Trusted Developer Utilities Proxy Execution
MITRE Version
2.0
Last Modified
May 12, 2026

View on MITRE ATT&CK ↗

Reported Context (2)

Malware (13)

VIEW MORE

People (4)

Threat Actors (4)

MITRE ATT&CK (39)

VIEW MORE

Vendors (7)

Products (18)

VIEW MORE

Tools (10)

Industries (3)

Countries (6)

Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.