BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category
  • Encoded VBScript executed High Execution

    Attackers tend to hide their malicious behavior in many ways, one of which is obfuscating their code via encoding.

    Indicator:

    Process action type = execution AND target process cmd = *vbscript.encode*

    ATT&CK tactics: Execution (TA0002) Defense Evasion (TA0005)
    ATT&CK techniques: Command and Scripting Interpreter: JavaScript (T1059.007) Deobfuscate/Decode Files or Information (T1140)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11