Microsoft.Workflow.Compiler.exe

type: OSBinaries
A utility included with .NET that is capable of compiling and executing C# or VB.net code.

Full path

C:\Windows\Microsoft.Net\Framework64\v4.0.30319\Microsoft.Workflow.Compiler.exe

Commands

  1. ExecuteUser T1127

    Compile and run code

    Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}

    Compile and execute C# or VB.net code in a XOML file referenced in the first argument (any extension accepted).

    os: Windows 10S, Windows 11

    Execute: VB.NetExecute: Csharp

  2. ExecuteUser T1127

    Compile and run code

    Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}

    Compile and execute C# or VB.net code in a XOML file referenced in the test.txt file.

    os: Windows 10S, Windows 11

    Execute: XOML

  3. AWL BypassUser T1127

    Compile and run code

    Microsoft.Workflow.Compiler.exe {PATH} {PATH:.log}

    Compile and execute C# or VB.net code in a XOML file referenced in the test.txt file.

    os: Windows 10S, Windows 11

    Execute: XOML

Detection

Resources

acknowledgement: Matt Graeber @mattifestation, John Bergbom @BergbomJohn, FortyNorth Security @FortyNorthSec, Bank Security @Bank_Security