WindowsT1127

>Aspnet_Compiler.exe

ASP.NET Compilation Tool

Default Executable Paths

c:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
c:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe

Integrity & Metadata

Category Count: 1 weaponized patterns
Forensics & Triage Insight

Documented in LOLBAS project by Jimmy (@bohops).

Detection Engineering Notes

Monitor process creation events where FileName is "Aspnet_Compiler.exe" or command line references known attack arguments.

Executive Summary & AI Quick Reference

High-Fidelity Telemetry Profile

Aspnet_Compiler.exe is a native utility pre-installed on Windows systems. Threat actors and red teams abuse Aspnet_Compiler.exe as a Living-off-the-Land Binary (LOLBin) to achieve Defense Evasion without triggering traditional antivirus file-hash alerts. Legitimate system administrators use it for routine administration, making behavioral command-line telemetry essential for differentiation.

Primary Abused Tactics
Defense Evasion
Minimum Privilege
User
Key Telemetry Source
Sysmon 1 / 4688
ATT&CK Mapping
T1127

Weaponized Parameters & Proof-of-Concepts

Documented attack commands, parameter flags, and privilege prerequisites.

1 documented methods
Filter Purpose:
Defense EvasionPrivileges: User
T1127: Technique T1127

Execute C# code with the Build Provider and proper folder structure in place.

C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe -v none -p C:\users\cpl.internal\desktop\asptest\ -f C:\users\cpl.internal\desktop\asptest\none -u

SIEM & EDR Detection Rules

Production telemetry rules configured for Microsoft Defender, Sigma, and Splunk.

Telemetry & SIEM Detection Suite (Aspnet_Compiler.exe)

Validated against MITRE T1127
Aspnet_Compiler.exe Microsoft Defender Querykql
1// Microsoft Defender XDR / Microsoft Sentinel
2// Tactic: Defense Evasion
3DeviceProcessEvents
4| where FileName =~ "Aspnet_Compiler.exe"
5| where ProcessCommandLine has_any ("Aspnet_Compiler")
6| project
7 Timestamp,
8 DeviceName,
9 AccountName,
10 InitiatingProcessParentFileName,
11 InitiatingProcessFileName,
12 InitiatingProcessCommandLine,
13 FileName,
14 FolderPath,
15 ProcessCommandLine,
16 MD5,
17 SHA256
18| sort by Timestamp desc

Mitigation, Hardening & Prevention

Recommended defensive controls to block or constrain Aspnet_Compiler.exe abuse.

Application Whitelisting

Enforce Windows Defender Application Control (WDAC) or AppLocker publisher rules to prevent execution outside approved enterprise administration scripts.

Attack Surface Reduction

Enable ASR rules: Block executable content from email client and webmail and Block Office applications from creating child processes spawning Aspnet_Compiler.exe.

Behavioral Alerting

Deploy the KQL, Sigma, and Splunk detection queries below. Alert on anomalous child processes, web requests to unrated external IPs, or encoded payload strings.

Frequently Asked Questions (FAQ) • Aspnet_Compiler.exe

Key operational questions and defensive answers about Aspnet_Compiler.exe LOLBin tradecraft.

What is Aspnet_Compiler.exe and why is it classified as a LOLBin?

Aspnet_Compiler.exe is a legitimate, pre-installed or trusted utility on Windows. It is classified as a Living-off-the-Land Binary (LOLBin) because adversaries abuse its built-in functionality to perform malicious operations—such as Defense Evasion—without dropping custom malware binaries on disk.

How do threat actors abuse Aspnet_Compiler.exe in cyber intrusions?

Adversaries leverage Aspnet_Compiler.exe to execute stealthy actions while evading signature-based security controls. For example, attackers execute commands like "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe -v none -p C:\users\cpl.internal\desktop\asptest\ -f C:\users\cpl.internal\desktop\asptest\none -u" to achieve Defense Evasion, masquerading behind legitimate system process lineage.

How can SOC analysts detect suspicious Aspnet_Compiler.exe activity?

Detection engineers monitor process creation events (Windows Event ID 4688 or Sysmon Event ID 1; Linux auditd EXECVE; macOS Endpoint Security) inspecting anomalous command line arguments, unusual parent-child process relationships (e.g. Office apps or web servers spawning Aspnet_Compiler.exe), and unexpected network connections.

What MITRE ATT&CK techniques does Aspnet_Compiler.exe map to?

Aspnet_Compiler.exe maps to MITRE ATT&CK technique(s): T1127. These techniques cover adversary actions across tactics such as Defense Evasion, Execution, Persistence, and Command and Control.

How can organizations mitigate and restrict Aspnet_Compiler.exe?

Mitigation strategies include implementing Application Control policies (AppLocker or Windows Defender Application Control - WDAC), enforcing Attack Surface Reduction (ASR) rules, configuring strict privilege separation (disallowing standard users from running sensitive switches), and alerting on execution from non-standard directories.

Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point