Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0332 — Detection Strategy for AutoHotKey & AutoIT Abuse
DET0332

Detection Strategy for AutoHotKey & AutoIT Abuse

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0942 Analytic 0942
Windows

Detects execution of AutoHotKey or AutoIT interpreters or compiled scripts used for unauthorized automation, command execution, or payload delivery, correlated with anomalous process lineage, command-line arguments, or script creation events.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=10
[TimeWindow] Tuning this helps identify automation behavior outside expected user work hours.
[ParentProcessName] Used to isolate cases where AHK or AutoIT scripts are spawned by suspicious or unusual processes.
[ScriptExtension] Extensions such as .ahk, .au3, or unknown .exe names compiled from these.
[ChildProcessCount] Threshold for number of spawned children to detect automation or modular malware behavior.

Detected Techniques

1

Details

MITRE ID
DET0332
STIX ID
x-mitre-detection-strategy--a948dd3c-a8f3-4bc0-aec3-4c5264e7a012
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.