{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/windows-scripting/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["reconnaissance","discovery","lotl","living-off-the-land","windows-scripting"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eGatherNetworkInfo.vbs is a legitimate, built-in Windows administrative script located in \u0026quot;C:\\Windows\\System32\u0026quot; designed to assist in gathering system network information for troubleshooting purposes. Threat actors increasingly leverage this script as a Living-off-the-Land (LotL) technique to perform stealthy reconnaissance on compromised hosts. By executing this script, an attacker can obtain detailed network configuration, routing tables, and interface information without deploying additional malware. This technique is particularly effective for post-exploitation discovery, as the script is signed by Microsoft and exists in the baseline of many Windows installations. Defenders should monitor for unexpected execution of this script, especially when it is not initiated by standard system management tools or administrative workflows.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful execution of this technique allows unauthorized actors to map internal network segments, identify active network interfaces, and collect sensitive configuration data that facilitates further lateral movement and privilege escalation. While no specific victim counts are reported, this method has been observed in campaigns targeting government infrastructure and enterprise environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect non-standard execution of GatherNetworkInfo.vbs.\u003c/li\u003e\n\u003cli\u003eEstablish a baseline of legitimate administrative activity involving the Windows System32 directory to reduce false positives.\u003c/li\u003e\n\u003cli\u003eCorrelate execution events with parent process information to identify potential malicious actors or tools attempting to bypass standard script interpreters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T12:45:07Z","date_published":"2026-09-03T12:45:07Z","id":"https://feed.craftedsignal.io/briefs/2026-09-gather-network-info-vbs/","summary":"Adversaries are utilizing the native Windows script GatherNetworkInfo.vbs to perform system reconnaissance and collect network configuration data.","title":"Suspicious Reconnaissance Activity via GatherNetworkInfo.VBS","url":"https://feed.craftedsignal.io/briefs/2026-09-gather-network-info-vbs/"}],"language":"en","title":"CraftedSignal Threat Feed - Windows-Scripting","version":"https://jsonfeed.org/version/1.1"}