BIOC
Low
✕
Commonly abused AutoIT script connects to a remote host
AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context.
- Module:
- Platform Analytics
- Agent event type:
- Network
- Category:
- Exfiltration
- Status:
- Enabled
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Automated Exfiltration (T1020)
Indicator:
Network action type = outgoing , failed Process initiator signature = Signed , Weak Hash AND initiator signer = Autoit* AND Autoit* Host host os = windows
Preventable: yes