Skip to content

Hide Navigation Hide TOC

Malicious PE Execution by Microsoft Visual Studio Debugger (15c7904e-6ad1-4a45-9b46-5fb25df37fd2)

There is an option for a MS VS Just-In-Time Debugger "vsjitdebugger.exe" to launch specified executable and attach a debugger. This option may be used adversaries to execute malicious code by signed verified binary. The debugger is installed alongside with Microsoft Visual Studio package.

Cluster A Galaxy A Cluster B Galaxy B Level
Malicious PE Execution by Microsoft Visual Studio Debugger (15c7904e-6ad1-4a45-9b46-5fb25df37fd2) Sigma-Rules System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) Attack Pattern 1