Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0264 — Cross-Platform Detection of JavaScript Execution Abuse
DET0264

Cross-Platform Detection of JavaScript Execution Abuse

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN0733 Analytic 0733
Windows

Detects JavaScript execution through WSH (wscript.exe, cscript.exe) or HTA (mshta.exe), particularly when spawned from Office macros, web browsers, or abnormal user paths. Correlates script execution with outbound network activity or system modification.

WinEventLog:Sysmon EventCode=1 m365:defender ScriptBlockLogging + AMSI WinEventLog:Sysmon EventCode=7
[ParentProcess] Execution of wscript.exe, cscript.exe, or mshta.exe from suspicious parent like Excel or Outlook.
[ScriptPath] Script loaded from %TEMP%, user download folder, or via UNC/web path.
[TimeWindow] Execution of JavaScript during non-business or patch windows.
[UserContext] Execution by accounts not typically authorized for scripting (e.g., non-admin users).
[EntropyScore] Obfuscated JS with high entropy detected by AMSI or ScriptBlock logging.
AN0734 Analytic 0734
macOS

Detects JavaScript for Automation (JXA) via osascript or compiled scripts using OSAKit APIs. Flags execution involving system modification, inter-process scripting, or browser abuse.

macos:unifiedlog log stream with predicate 'eventMessage CONTAINS "osascript"' macos:osquery process_events macos:syslog /var/log/system.log
[ScriptLocation] Execution of JXA from user-controlled paths like ~/Downloads or /Volumes.
[ParentProcess] osascript invoked by third-party apps (VSCode, browsers, etc.).
[APIInvocation] Use of OSAKit API by apps not typically scripting-enabled.
AN0735 Analytic 0735
Linux

Detects Node.js or JavaScript interpreter execution from web shells, cron jobs, or local users. Correlates execution with reverse shell behavior, file modifications, or abnormal outbound connections.

auditd:SYSCALL execve linux:syslog /var/log/syslog
[ScriptPath] Script launched from /tmp, /var/tmp, or hidden dot directories.
[BinaryName] Custom compiled JS binaries like node_shell or interpreter disguises.
[UserExecutionContext] Execution by service accounts or low-privilege users running cron scripts.
[NetworkFollowUp] Connection attempts to C2 post-node.js execution.

Detected Techniques

1

Details

MITRE ID
DET0264
STIX ID
x-mitre-detection-strategy--6dd441e4-d264-4f7f-b145-9c122955c532
Analytics
3
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.