FsiAnyCpu.exe
32/64-bit FSharp (F#) Interpreter included with Visual Studio.
Full path
c:\Program Files (x86)\Microsoft Visual Studio\2019\Professional\Common7\IDE\CommonExtensions\Microsoft\FSharp\fsianycpu.exeCommands
Execute payload with Microsoft signed binary to bypass WDAC policies
fsianycpu.exe {PATH:.fsscript}Execute F# code via script file
os: Windows 10 2004 (likely previous and newer versions as well)
Execute payload with Microsoft signed binary to bypass WDAC policies
fsianycpu.exeExecute F# code via interactive command line
os: Windows 10 2004 (likely previous and newer versions as well)
Detection
- BlockRule https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules
- IOCFsiAnyCpu.exe execution may be suspicious on non-developer machines
- Sigma https://github.com/SigmaHQ/sigma/blob/6b34764215b0e97e32cbc4c6325fc933d2695c3a/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml
Code samples
Resources
acknowledgement: Nick Tyrer @NickTyrer, Jimmy @bohops