possible_malicious_use_of_mshtaexe_detector_sysmon_behavior
Description
None License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
Query · yara_l
events:
($selection1.metadata.product_event_type = "1" and ((re.regex($selection1.target.process.file.full_path, `.*\\mshta\.exe`) and (re.regex($selection1.target.process.command_line, `.*javascript.*`) or re.regex($selection1.target.process.command_line, `.*vbscript.*`) or re.regex($selection1.target.process.command_line, `.*\.hta.*`) or re.regex($selection1.target.process.command_line, `.*http.*`))) or (re.regex($selection1.target.process.file.full_path, `.*\\schtasks\.exe`) and re.regex($selection1.target.process.command_line, `.*/tr mshta\.exe.*`))))
condition:
$selection1