Tag
high
advisory
Suspicious PowerShell Execution via Windows Script Host
2 rules 1 TTPAdversaries may execute PowerShell commands through the Windows Script Host (wscript.exe or cscript.exe) using suspicious arguments, potentially bypassing traditional PowerShell execution policies and detection mechanisms.
Windows
powershell
wscript
cscript
execution
scripting
2r
1t
high
advisory
Suspicious Child Processes Spawned by WScript or CScript
2 rules 3 TTPsDetects suspicious processes spawned by WScript or CScript, a common technique used by adversaries to execute LOLBINs, PowerShell, or inject code into suspended processes for defense evasion.
Splunk Enterprise +2
wscript
cscript
lolbin
malware
defense-evasion
2r
3t