BIOC
High
✕
Encoded VBScript executed
Attackers tend to hide their malicious behavior in many ways, one of which is obfuscating their code via encoding.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Execution
- Status:
- Enabled
ATT&CK tactics: Execution (TA0002) Defense Evasion (TA0005)
ATT&CK techniques: Command and Scripting Interpreter: JavaScript (T1059.007) Deobfuscate/Decode Files or Information (T1140)
Indicator:
Process action type = execution AND target process cmd = *vbscript.encode*
Preventable: yes