MSBuild or DotNet Proxy Execution Detected
Detects potential abuse of MSBuild.exe or DotNet.exe as a proxy for executing arbitrary code. The rule identifies processes executing MSBuild or specific DotNet CLI operations (build, publish, test, pack) that do not originate from expected binary names, indicating a possible attempt to bypass application execution defenses using trusted developer utilities.
Microsoft Sentinel (KQL)

