Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0005 ✕
Download CSV Show ATT&CK heatmapMshta.exe spawns from a browser process Low 1 variation
Mshta is the Microsoft HTML Application Host. It executes HTML applications on Windows. Detected when a browser process has spawned mshta, which can be a potential attack vector.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Stealth (TA0005)ATT&CK techniques: System Binary Proxy Execution: Mshta (T1218.005)Required data: XDR AgentDetector tags: LOLBIN Execution AnalyticsAttacker's goals: Execute malicious code through system binary proxy execution to bypass application controls and security monitoring.Investigative actions: Examine the command line arguments passed to mshta for suspicious URLs or file paths. Check the browser process that spawned mshta for signs of compromise. Review network connections around the time of execution. Analyze any HTML applications (.hta files) that may have been executed.Variations
Mshta.exe spawns from a browser process that executes a script from a URL
Medium overridden
Mshta is the Microsoft HTML Application Host. It executes HTML applications on Windows. Detected when a browser process has spawned mshta, which can be a potential attack vector. overridden