AWL Bypass
AWL / Policy Bypass Windows
VSTest functionality may allow an adversary to executes their malware by wrapping it as a test method then build it to a .exe or .dll file to be later run by vstest.console.exe. This may both allow AWL bypass or defense bypass in general
Use Proxy Execution and AWL bypass, Adversaries may run malicious code embedded inside the test methods of crafted dll/exe