Skip to content
Threat Feed

Tag

Scripting

11 briefs RSS
medium advisory

PowerShell Core DLL Loaded By Non PowerShell Process

This threat brief details a detection for the suspicious loading of PowerShell Core DLLs by non-PowerShell processes, a technique often employed by attackers to execute PowerShell code stealthily and evade security monitoring.

defense-evasion scripting powershell
1r 1t
medium advisory

Suspicious Child Process Creation by Wscript or Cscript

Adversaries commonly use Wscript or Cscript to launch suspicious child processes, including LOLBINs and scripting interpreters, as a defense evasion and execution technique, which can lead to further system compromise or data destruction.

endpoint-detection defense-evasion execution LOLBIN scripting
1r 2t 1i
high advisory

XWiki Remote Code Execution via Unprotected Velocity Scripting API

XWiki is vulnerable to remote code execution due to an improperly protected scripting API, allowing users with script rights to bypass the Velocity scripting API sandbox and execute arbitrary code, leading to full instance compromise.

xwiki rce velocity scripting CVE-2026-33229
2r 2t
high advisory

Command and Scripting Interpreter via Windows Scripts

This rule detects the execution of PowerShell, PowerShell ISE, or Cmd spawned from Windows Script Host or MSHTA, indicating potential abuse of scripting interpreters to execute malicious commands or scripts on Windows systems.

Microsoft Defender XDR +8 execution scripting windows
2r 1t
high advisory

Suspicious PowerShell Execution via Windows Script Host

Adversaries may execute PowerShell commands through the Windows Script Host (wscript.exe or cscript.exe) using suspicious arguments, potentially bypassing traditional PowerShell execution policies and detection mechanisms.

Windows powershell wscript cscript execution scripting
2r 1t
medium advisory

Windows Script Execution from Archive File

This rule identifies attempts to execute Jscript/Vbscript files from an archive file, a common delivery method for malicious scripts on Windows systems.

M365 Defender +2 execution windows scripting archive
2r 3t
medium advisory

Execution of Downloaded Windows Script

This rule identifies the creation and execution of a Windows script downloaded from the internet, which adversaries may leverage for initial access and execution by exploiting unusual parent-child process relationships and script attributes.

Windows execution scripting
2r 5t
high advisory

MSBuild Executed by Scripting Host

Detects the suspicious spawning of MSBuild.exe by Windows Script Host processes (cscript.exe or wscript.exe), a behavior often associated with malware executing malicious MSBuild processes via scripts.

Splunk Enterprise +2 msbuild scripting defense-evasion endpoint
2r 1t
high advisory

Detection of Windows AutoIt3 Execution

Detects execution of AutoIt3, a scripting language used for Windows GUI automation, often abused by attackers to automate malicious actions such as executing malware, potentially leading to unauthorized code execution and system compromise.

AutoIt3 scripting malware execution windows
2r 1t
medium advisory

Windows Script Execution from Archive File

This rule detects attempts to execute Jscript/Vbscript files from archive files, a common method for delivering malicious scripts by identifying unusual parent-child process relationships where scripting utilities are launched from archive programs, indicating potential exploitation.

Windows Script Host +2 execution archive scripting windows
2r 3t
medium advisory

Windows Script Host Executing PowerShell

Detects PowerShell execution initiated by cscript.exe or wscript.exe, commonly used by attackers for initial access or payload delivery.

Windows Script Host +1 initial-access powershell windows scripting
2r 4t