Suspicious MSBuild Rename
Masquerading, Trusted Developer Utilities Proxy Execution, Rename System Utilities, MSBuild
Masquerading, Trusted Developer Utilities Proxy Execution, Rename System Utilities, MSBuild
Command and Scripting Interpreter, PowerShell
Modify Registry
System Binary Proxy Execution, Rundll32
Command and Scripting Interpreter, PowerShell