BIOC Informational

VBScript execution from the command line

Attackers may run VBScript code from the command line using signed processes such as Mshta.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Execution
Status:
Enabled
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter: Visual Basic (T1059.005)
Indicator:

Process action type = execution AND target process cmd = *createobject(*

Preventable: yes