LoFP LoFP / legitimate use of dnx.exe by legitimate user

Techniques

Sample rules

Potential Application Whitelisting Bypass via Dnx.EXE

Description

Detects the execution of Dnx.EXE. The Dnx utility allows for the execution of C# code. Attackers might abuse this in order to bypass application whitelisting.

Detection logic

condition: selection
selection:
  Image|endswith: \dnx.exe