Most Popular Detection 2026: Regsvr32 and MSBuild Living-off-the-Land Code Execu
Detects the abuse of built-in Windows binaries 'regsvr32.exe' and 'msbuild.exe' for proxy execution. Specifically, it flags 'regsvr32.exe' loading remote scriptlets via HTTP and 'msbuild.exe' processing project files containing inline tasks, which are common techniques used to execute arbitrary malicious code while bypassing security controls.
SentinelOne

