[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqJSGs4_ZymDDutKo2Tlgokupu-JbQARsGn12k8guEUA":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},129,"What steps are needed to load a PE file (like Mimikatz) from memory using MSBuild?","To load a PE file from memory using MSBuild, you write C# code within an Inline Task to read the PE bytes and execute them, similar to loading a .NET assembly reflectively. The XML file must specify `TaskFactory=\"CodeTaskFactory\"` and the correct path to `Microsoft.Build.Tasks.v4.0.dll`. A crucial detail is that on 64-bit systems, you must use the 64-bit MSBuild executable at `C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\msbuild.exe` to avoid errors. The article [Use MSBuild To Do More](\u002Fnews\u002Fuse-msbuild-to-do-more) provides a working example and points to related research on [Loading PE files into memory via .NET](\u002Fnews\u002Floading-pe-files-into-memory-via-net).","\u003Cp>To load a PE file from memory using MSBuild, you write C# code within an Inline Task to read the PE bytes and execute them, similar to loading a .NET assembly reflectively. The XML file must specify `TaskFactory=&quot;CodeTaskFactory&quot;` and the correct path to `Microsoft.Build.Tasks.v4.0.dll`. A crucial detail is that on 64-bit systems, you must use the 64-bit MSBuild executable at `C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\msbuild.exe` to avoid errors. The article [Use MSBuild To Do More](\u002Fnews\u002Fuse-msbuild-to-do-more) provides a working example and points to related research on [Loading PE files into memory via .NET](\u002Fnews\u002Floading-pe-files-into-memory-via-net).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fuse-msbuild-to-do-more\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-steps-are-needed-to-load-a-pe-file-like-mimikatz-from-memory-using-msbuild-1777485061666","PE file execution, reflective loading, mimikatz, MSBuild, 64-bit",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},35,"Use MSBuild To Do More","use-msbuild-to-do-more","Learn advanced MSBuild techniques to execute PowerShell commands, PE files, shellcode, and achieve persistence in VisualStudio using inline tasks and XML files.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, Casey Smith @subTee updated a series of research progress on \"MSBuild\", which greatly inspired me.\u003C\u002Fp>\u003Cp>Based on his publicly available POC and combined with my research insights, this article will introduce the following MSBuild application techniques:\u003C\u002Fp>\u003Cul>\u003Cli>Execute PowerShell Commands\u003C\u002Fli>\u003Cli>Execute PE file\u003C\u002Fli>\u003Cli>Execute Shellcode\u003C\u002Fli>\u003Cli>VisualStudio Persistence\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>MSBuild is an abbreviation for Microsoft Build Engine, representing Microsoft and Visual Studio's new build platform.\u003C\u002Fp>\u003Cp>MSBuild can compile .NET project files in environments without Visual Studio installed.\u003C\u002Fp>\u003Cp>MSBuild can compile XML files of specific formats.\u003C\u002Fp>\u003Cp>For more basic knowledge, please refer to the following links:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fdd393574.aspx\u003C\u002Fp>\u003Ch2>0x02 Common Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Compile XML file and execute code\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\" ?-->\u003Cbr>\u003Cproject xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fdeveloper\u002Fmsbuild\u002F2003\">\u003Cbr>  \u003Ctarget name=\"PrintCurrentDateTime\">\u003Cbr>    \u003Cmessage text=\"The current date and time is: $([System.DateTime]::Now).\">\u003Cbr>  \u003C\u002Fmessage>\u003C\u002Ftarget>\u003Cbr>\u003C\u002Fproject>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save as test.csproj\u003C\u002Fp>\u003Cp>Execute in cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.Net\\Framework\\v4.0.30319\\msbuild.exe test.csproj\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The current time will be displayed in the cmd output, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019810941_0_250b7b7640.jpeg\">\u003C\u002Fp>\u003Ch3>2. Compile XML file to generate exe\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>class Test\u003Cbr>{\u003Cbr>    static void Main()\u003Cbr>    {\u003Cbr>        Console.WriteLine(\"Hello world\");\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save as hello.cs\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cproject xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fdeveloper\u002Fmsbuild\u002F2003\">\u003Cbr>    \u003Ctarget name=\"Compile\">\u003Cbr>        \u003Ccsc sources=\"hello.cs\" outputassembly=\"hello.exe\">\u003Cbr>    \u003C\u002Fcsc>\u003C\u002Ftarget>\u003Cbr>\u003C\u002Fproject>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save as hello.csproj\u003C\u002Fp>\u003Cp>Place hello.cs and hello.csproj in the same directory\u003C\u002Fp>\u003Cp>Execute in cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.Net\\Framework\\v4.0.30319\\msbuild.exe hello.csproj\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Can compile and generate hello.exe\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019822408_1_09a92230e7.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The compilation file only needs to satisfy the XML file format, the file extension can be arbitrary\u003C\u002Fp>\u003Ch2>0x03 Extended Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In .NET Framework 4.0, a new feature \"Inline Tasks\" is supported, included in the UsingTask element, which can be used to execute C# code within XML files\u003C\u002Fp>\u003Cp>For detailed introduction, refer to the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fdd722601.aspx?f=255&amp;MSPPError=-2147217396\u003C\u002Fp>\u003Ch3>1. HelloWorld Example\u003C\u002Fh3>\u003Cp>Save the following code as helloworld:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cproject toolsversion=\"4.0\" xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fdeveloper\u002Fmsbuild\u002F2003\">\u003Cbr>  \u003Ctarget name=\"Hello\">\u003Cbr>   \u003Chelloworld>\u003Cbr>  \u003C\u002Fhelloworld>\u003C\u002Ftarget>\u003Cbr>  \u003Cusingtask\u003Cbr>    TaskName=\"HelloWorld\"\u003Cbr>    TaskFactory=\"CodeTaskFactory\"\u003Cbr>    AssemblyFile=\"C:\\Windows\\Microsoft.Net\\Framework\\v4.0.30319\\Microsoft.Build.Tasks.v4.0.dll\" &gt;\u003Cbr>    \u003Cparametergroup>\u003Cbr>    \u003Ctask>\u003Cbr>      \u003Cusing namespace=\"System\">  \u003Cbr>      \u003Ccode type=\"Fragment\" language=\"cs\">\u003Cbr>        \u003C!--[CDATA[\u003Cbr-->\t\t\t    Console.WriteLine(\"Hello World\");\t\t\u003Cbr>        ]]&gt;\u003Cbr>      \u003C\u002Fcode>\u003Cbr>    \u003C\u002Fusing>\u003C\u002Ftask>\u003Cbr>    \u003Cbr>\u003C\u002Fparametergroup>\u003C\u002Fusingtask\u003Cbr>\u003C\u002Fproject>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The filename can be arbitrary\u003C\u002Fp>\u003Cp>Execute in cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\msbuild.exe helloworld\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>cmd outputs helloworld\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019832548_2_ae432782ba.jpeg\">\u003C\u002Fp>\u003Ch3>2. Execute PowerShell command\u003C\u002Fh3>\u003Cp>Refer to the POC shared by Casey, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F6b236083da2fd6ddff216e434f257614\u003C\u002Fp>\u003Cp>The POC has converted C# code into XML file format, with the following points requiring attention during writing:\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019850414_3_97ca40c11a.jpeg\">\u003C\u002Fp>\u003Cp>Marker 1 TaskName can be modified, but the names in both positions must correspond\u003C\u002Fp>\u003Cp>Marker 2 is a fixed format: TaskFactory=\"CodeTaskFactory\"\u003C\u002Fp>\u003Cp>The path for Marker 3 may vary across different systems, the accurate one is:\u003C\u002Fp>\u003Cp>\"$(MSBuildToolsPath)\\Microsoft.Build.Tasks.v4.0.dll\"\u003C\u002Fp>\u003Cp>The default system installation path is:\u003C\u002Fp>\u003Cp>\"C:\\Windows\\Microsoft.Net\\Framework\\v4.0.30319\\Microsoft.Build.Tasks.v4.0.dll\"\u003C\u002Fp>\u003Cp>Marker 4 is a simple HelloWorld output example\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019863390_4_84750d4e85.jpeg\">\u003C\u002Fp>\u003Cp>Marker 5 is a fixed format, defined as public class ClassExample : Task, ITask\u003C\u002Fp>\u003Cp>The actual POC test is shown in the figure, successfully executing PowerShell commands\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019867857_5_a32b54461b.jpeg\">\u003C\u002Fp>\u003Ch3>3. Execute PE file\u003C\u002Fh3>\u003Cp>The POC address shared by Casey is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002Fca477b4d19c885bec05ce238cbad6371\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019871509_6_c9e22f030e.png\">\u003C\u002Fp>\u003Cp>However, the uploaded file was truncated, causing some code to be unviewable, so I attempted to implement it myself\u003C\u002Fp>\u003Cp>Combining previously researched code, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F00cdac8990584bd2c2fe\u003C\u002Fp>\u003Cp>Referring to the XML format mentioned above, I wrote code to load the 64-bit mimikatz.exe in memory within Inline Tasks. The download address for the implementation code is:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Execute in cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\msbuild.exe aa\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Error reported, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019876450_7_8cba6d4c69.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Need to switch to the 64-bit .NET Framework. The original code does not require modification, just needs to be loaded using the 64-bit .NET Framework\u003C\u002Fp>\u003Cp>Execute in cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\msbuild.exe aa\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Loaded successfully, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019881320_8_1da93111fa.png\">\u003C\u002Fp>\u003Ch3>4. Execute shellcode\u003C\u002Fh3>\u003Cp>Reference from https:\u002F\u002Fgist.github.com\u002FsubTee\u002Fa06d4ae23e2517566c52\u003C\u002Fp>\u003Cp>Generate 32-bit shellcode using msf:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use windows\u002Fexec\u003Cbr>set CMD calc.exe\u003Cbr>set EXITFUNC thread\u003Cbr>generate -t csharp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Similarly, combined with the xml format mentioned above, write code to execute shellcode in Inline Tasks. The implementation code download address is:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Save as SimpleTasks.csproj, execute in cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\msbuild.exe SimpleTasks.csproj\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown, successfully executed shellcode to launch calculator\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019885562_9_a71a7de2c1.png\">\u003C\u002Fp>\u003Cp>On 64-bit systems, first replace the shellcode with 64-bit version, then execute using 64-bit .NET Framework. Code download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>As shown, successfully executed 64-bit shellcode\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019888301_10_3f8981c373.png\">\u003C\u002Fp>\u003Ch3>5. VisualStudio Persistence\u003C\u002Fh3>\u003Cp>In 'Pay close attention to your download code——Visual Studio trick to run code when building', code execution via Visual Studio's .csproj file was introduced. Similarly, Inline Tasks can be applied here. The implementation code has been uploaded, address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Modify the .csproj file in the VS project by adding the above code to achieve shellcode execution during VS project compilation\u003C\u002Fp>\u003Cp>As shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019890218_11_030e135040.png\">\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Code execution achieved via MSBuild has the following characteristics:\u003C\u002Fp>\u003Cul>\u003Cli>Can bypass application whitelist\u003C\u002Fli>\u003Cli>Provides a method to directly execute shellcode\u003C\u002Fli>\u003Cli>Executes PE files in memory\u003C\u002Fli>\u003Cli>Combines phishing and backdoor implementation with Visual Studio\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Therefore, it is recommended to enhance monitoring and restrictions on msbuild.exe in the system.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The relevant POC code mentioned in the article has been uploaded to GitHub at:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, Casey Smith @subTee updated a series of research progress on \"MSBuild\", which greatly inspired me.\u003C\u002Fp>\u003Cp>Based on his publicly available POC and combined with my research insights, this article will introduce the following MSBuild application techniques:\u003C\u002Fp>\u003Cul>\u003Cli>Execute PowerShell Commands\u003C\u002Fli>\u003Cli>Execute PE file\u003C\u002Fli>\u003Cli>Execute Shellcode\u003C\u002Fli>\u003Cli>VisualStudio Persistence\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>MSBuild is an abbreviation for Microsoft Build Engine, representing Microsoft and Visual Studio's new build platform.\u003C\u002Fp>\u003Cp>MSBuild can compile .NET project files in environments without Visual Studio installed.\u003C\u002Fp>\u003Cp>MSBuild can compile XML files of specific formats.\u003C\u002Fp>\u003Cp>For more basic knowledge, please refer to the following links:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fdd393574.aspx\u003C\u002Fp>\u003Ch2>0x02 Common Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Compile XML file and execute code\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\" ?-->\u003Cbr>\u003Cproject xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fdeveloper\u002Fmsbuild\u002F2003\">\u003Cbr>  \u003Ctarget name=\"PrintCurrentDateTime\">\u003Cbr>    \u003Cmessage text=\"The current date and time is: $([System.DateTime]::Now).\">\u003Cbr>  \u003C\u002Fmessage>\u003C\u002Ftarget>\u003Cbr>\u003C\u002Fproject>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save as test.csproj\u003C\u002Fp>\u003Cp>Execute in cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.Net\\Framework\\v4.0.30319\\msbuild.exe test.csproj\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The current time will be displayed in the cmd output, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019810941_0_250b7b7640-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Compile XML file to generate exe\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>class Test\u003Cbr>{\u003Cbr>    static void Main()\u003Cbr>    {\u003Cbr>        Console.WriteLine(\"Hello world\");\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save as hello.cs\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cproject xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fdeveloper\u002Fmsbuild\u002F2003\">\u003Cbr>    \u003Ctarget name=\"Compile\">\u003Cbr>        \u003Ccsc sources=\"hello.cs\" outputassembly=\"hello.exe\">\u003Cbr>    \u003C\u002Fcsc>\u003C\u002Ftarget>\u003Cbr>\u003C\u002Fproject>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save as hello.csproj\u003C\u002Fp>\u003Cp>Place hello.cs and hello.csproj in the same directory\u003C\u002Fp>\u003Cp>Execute in cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.Net\\Framework\\v4.0.30319\\msbuild.exe hello.csproj\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Can compile and generate hello.exe\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019822408_1_09a92230e7-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The compilation file only needs to satisfy the XML file format, the file extension can be arbitrary\u003C\u002Fp>\u003Ch2>0x03 Extended Usage\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In .NET Framework 4.0, a new feature \"Inline Tasks\" is supported, included in the UsingTask element, which can be used to execute C# code within XML files\u003C\u002Fp>\u003Cp>For detailed introduction, refer to the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fdd722601.aspx?f=255&amp;MSPPError=-2147217396\u003C\u002Fp>\u003Ch3>1. HelloWorld Example\u003C\u002Fh3>\u003Cp>Save the following code as helloworld:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cproject toolsversion=\"4.0\" xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fdeveloper\u002Fmsbuild\u002F2003\">\u003Cbr>  \u003Ctarget name=\"Hello\">\u003Cbr>   \u003Chelloworld>\u003Cbr>  \u003C\u002Fhelloworld>\u003C\u002Ftarget>\u003Cbr>  \u003Cusingtask\u003Cbr>    TaskName=\"HelloWorld\"\u003Cbr>    TaskFactory=\"CodeTaskFactory\"\u003Cbr>    AssemblyFile=\"C:\\Windows\\Microsoft.Net\\Framework\\v4.0.30319\\Microsoft.Build.Tasks.v4.0.dll\" &gt;\u003Cbr>    \u003Cparametergroup>\u003Cbr>    \u003Ctask>\u003Cbr>      \u003Cusing namespace=\"System\">  \u003Cbr>      \u003Ccode type=\"Fragment\" language=\"cs\">\u003Cbr>        \u003C!--[CDATA[\u003Cbr-->\t\t\t    Console.WriteLine(\"Hello World\");\t\t\u003Cbr>        ]]&gt;\u003Cbr>      \u003C\u002Fcode>\u003Cbr>    \u003C\u002Fusing>\u003C\u002Ftask>\u003Cbr>    \u003Cbr>\u003C\u002Fparametergroup>\u003C\u002Fusingtask\u003Cbr>\u003C\u002Fproject>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The filename can be arbitrary\u003C\u002Fp>\u003Cp>Execute in cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\msbuild.exe helloworld\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>cmd outputs helloworld\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019832548_2_ae432782ba-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Execute PowerShell command\u003C\u002Fh3>\u003Cp>Refer to the POC shared by Casey, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F6b236083da2fd6ddff216e434f257614\u003C\u002Fp>\u003Cp>The POC has converted C# code into XML file format, with the following points requiring attention during writing:\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019850414_3_97ca40c11a-1.jpeg\">\u003C\u002Fp>\u003Cp>Marker 1 TaskName can be modified, but the names in both positions must correspond\u003C\u002Fp>\u003Cp>Marker 2 is a fixed format: TaskFactory=\"CodeTaskFactory\"\u003C\u002Fp>\u003Cp>The path for Marker 3 may vary across different systems, the accurate one is:\u003C\u002Fp>\u003Cp>\"$(MSBuildToolsPath)\\Microsoft.Build.Tasks.v4.0.dll\"\u003C\u002Fp>\u003Cp>The default system installation path is:\u003C\u002Fp>\u003Cp>\"C:\\Windows\\Microsoft.Net\\Framework\\v4.0.30319\\Microsoft.Build.Tasks.v4.0.dll\"\u003C\u002Fp>\u003Cp>Marker 4 is a simple HelloWorld output example\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019863390_4_84750d4e85-1.jpeg\">\u003C\u002Fp>\u003Cp>Marker 5 is a fixed format, defined as public class ClassExample : Task, ITask\u003C\u002Fp>\u003Cp>The actual POC test is shown in the figure, successfully executing PowerShell commands\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019867857_5_a32b54461b-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Execute PE file\u003C\u002Fh3>\u003Cp>The POC address shared by Casey is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002Fca477b4d19c885bec05ce238cbad6371\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019871509_6_c9e22f030e-1.png\">\u003C\u002Fp>\u003Cp>However, the uploaded file was truncated, causing some code to be unviewable, so I attempted to implement it myself\u003C\u002Fp>\u003Cp>Combining previously researched code, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgist.github.com\u002FsubTee\u002F00cdac8990584bd2c2fe\u003C\u002Fp>\u003Cp>Referring to the XML format mentioned above, I wrote code to load the 64-bit mimikatz.exe in memory within Inline Tasks. The download address for the implementation code is:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Execute in cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\msbuild.exe aa\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Error reported, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019876450_7_8cba6d4c69-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Need to switch to the 64-bit .NET Framework. The original code does not require modification, just needs to be loaded using the 64-bit .NET Framework\u003C\u002Fp>\u003Cp>Execute in cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\msbuild.exe aa\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Loaded successfully, as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019881320_8_1da93111fa-1.png\">\u003C\u002Fp>\u003Ch3>4. Execute shellcode\u003C\u002Fh3>\u003Cp>Reference from https:\u002F\u002Fgist.github.com\u002FsubTee\u002Fa06d4ae23e2517566c52\u003C\u002Fp>\u003Cp>Generate 32-bit shellcode using msf:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use windows\u002Fexec\u003Cbr>set CMD calc.exe\u003Cbr>set EXITFUNC thread\u003Cbr>generate -t csharp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Similarly, combined with the xml format mentioned above, write code to execute shellcode in Inline Tasks. The implementation code download address is:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Save as SimpleTasks.csproj, execute in cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\msbuild.exe SimpleTasks.csproj\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown, successfully executed shellcode to launch calculator\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019885562_9_a71a7de2c1-1.png\">\u003C\u002Fp>\u003Cp>On 64-bit systems, first replace the shellcode with 64-bit version, then execute using 64-bit .NET Framework. Code download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>As shown, successfully executed 64-bit shellcode\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019888301_10_3f8981c373-1.png\">\u003C\u002Fp>\u003Ch3>5. VisualStudio Persistence\u003C\u002Fh3>\u003Cp>In 'Pay close attention to your download code——Visual Studio trick to run code when building', code execution via Visual Studio's .csproj file was introduced. Similarly, Inline Tasks can be applied here. The implementation code has been uploaded, address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Modify the .csproj file in the VS project by adding the above code to achieve shellcode execution during VS project compilation\u003C\u002Fp>\u003Cp>As shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019890218_11_030e135040-1.png\">\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Code execution achieved via MSBuild has the following characteristics:\u003C\u002Fp>\u003Cul>\u003Cli>Can bypass application whitelist\u003C\u002Fli>\u003Cli>Provides a method to directly execute shellcode\u003C\u002Fli>\u003Cli>Executes PE files in memory\u003C\u002Fli>\u003Cli>Combines phishing and backdoor implementation with Visual Studio\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Therefore, it is recommended to enhance monitoring and restrictions on msbuild.exe in the system.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The relevant POC code mentioned in the article has been uploaded to GitHub at:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1654,"Onedaysec",4,"published","2026-02-02T08:19:47.664Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"MSBuild Techniques: Execute PowerShell, PE Files, Shellcode & Persistence","MSBuild, PowerShell execution, PE file execution, shellcode, VisualStudio persistence, inline tasks, Casey Smith, .NET Framework, XML compilation, C# code execution",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],131,130,128,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.255Z","2026-07-23T16:01:03.714Z","draft","2026-07-23T16:03:53.340Z"]