BIOC Informational

Execution of commonly abused AutoIT script

AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Execution
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Script Proxy Execution (T1216)
Indicator:

Process action type = execution AND process execution signature = Signed , Weak Hash AND process execution signer = Autoit Consulting* Host host os = windows

Preventable: yes