Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0440 — Detecting PowerShell Execution via SyncAppvPublishingServer.vbs Proxy Abuse
DET0440

Detecting PowerShell Execution via SyncAppvPublishingServer.vbs Proxy Abuse

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1220 Analytic 1220
Windows

Execution of SyncAppvPublishingServer.vbs through wscript.exe with a command-line containing embedded PowerShell, proxying malicious PowerShell execution through a Microsoft-signed VBScript interpreter to evade detection and restrictions.

WinEventLog:Sysmon EventCode=1 WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=10
[CommandLineRegex] Detects embedded PowerShell commands in SyncAppvPublishingServer.vbs invocation, e.g., `{powershell -nop -enc ...}`
[ScriptInterpreter] May vary between `wscript.exe`, `cscript.exe`, or called via `cmd.exe`
[PowerShellObfuscationScore] Used to detect encoding, obfuscation, or entropy level in embedded PowerShell payloads
[TimeWindow] Time delta between VBScript proxy invocation and PowerShell payload execution

Detected Techniques

1

Details

MITRE ID
DET0440
STIX ID
x-mitre-detection-strategy--ba3578d1-5913-4ed1-ab83-473a39b63f7d
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.