Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0205 — Detect XSL Script Abuse via msxsl and wmic
DET0205

Detect XSL Script Abuse via msxsl and wmic

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0581 Analytic 0581
Windows

Execution of XSL scripts via msxsl.exe or wmic.exe using embedded JScript or VBScript for proxy execution. Detection correlates process creation, command-line patterns, and module load behavior of scripting components (e.g., jscript.dll).

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7
[CommandLinePattern] May need to tune based on encoded input or custom extensions (e.g., .jpeg instead of .xsl).
[ParentProcess] Legitimate administrative or developer tools may use msxsl; validate the parent process chain.
[TimeWindow] Temporal correlation window between script engine DLL load and suspicious process spawn.
[RemoteXSLDomainWhitelist] Filter known safe URLs used by enterprise for XSL transformations.

Detected Techniques

1

Details

MITRE ID
DET0205
STIX ID
x-mitre-detection-strategy--4994627c-216b-4832-90cf-074d3e9013e4
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.