MSBuild.exe Inline Task Execution for Application Whitelisting Bypass
Detects the abuse of MSBuild.exe to execute arbitrary code. The rule monitors for three primary suspicious behaviors: MSBuild spawning suspicious child processes indicative of inline task execution, MSBuild being launched with project file arguments from non-standard or untrusted parents, and MSBuild being launched without a project file (implying piped or inline payload delivery).
SentinelOne

