Trusted Developer Utilities Proxy Execution: MSBuild

Threat Actors may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio. It handles XML formatted project files that define requirements for loading and building various platforms and configurations.

ID: ATAGS-T1108.003
Sub-technique of:  ATAGS-T1108
Tactic: Defense Evasion
Targeted Components: Supply Chain
Responsibility: Provider
Created: 18 April 2026
Last Modified: 18 April 2026

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.