Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0506 — Detecting Mshta-based Proxy Execution via Suspicious HTA or Script Invocation
DET0506

Detecting Mshta-based Proxy Execution via Suspicious HTA or Script Invocation

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1397 Analytic 1397
Windows

Detection of mshta.exe execution where command-line arguments reference remote or local HTA/script content (VBScript/JScript) followed by subsequent file creation, network retrieval, or process spawning that indicates payload execution outside standard Internet Explorer security context. Correlation includes parent process lineage, command-line inspection, and network connection creation to untrusted or anomalous endpoints.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Sysmon EventCode=11
[CommandLinePattern] Regex patterns for mshta.exe arguments referencing remote HTA/script content; may need tuning to exclude known-good internal scripts.
[SuspiciousParentProcesses] List of parent processes considered suspicious when spawning mshta.exe (e.g., Office applications, script interpreters).
[AllowedHTASources] Whitelist of domains/paths from which legitimate HTAs are executed.
[TimeWindow] Time threshold for correlating mshta.exe execution with subsequent network connections or file creations.

Detected Techniques

1

Stealth (1)

Details

MITRE ID
DET0506
STIX ID
x-mitre-detection-strategy--8d06728f-5b50-4925-a05c-4d56b17ba5d2
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.