Cross-source coverage

T1064 / ATT&CK

Scripting

ATT&CK has deprecated this technique with no replacement. Rules still tag it.

18 rules across 2 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

This technique has been deprecated. Please use Command and Scripting Interpreter where appropriate.

Adversaries may use scripts to aid in operations and perform multiple actions that would otherwise be manual. Scripting is useful for speeding up operational tasks and reducing the time required to gain access to critical resources. Some scripting languages may be used to bypass process monitoring mechanisms by directly interacting with the operating system at an API level instead of calling other programs. Common scripting languages for Windows include VBScript and PowerShell but could also be in the form of command-line batch scripts.

Scripts can be embedded inside Office documents as macros that can be set to execute when files used in Spearphishing Attachment and other types of spearphishing are opened. Malicious embedded macros are an alternative means of execution than software exploitation through Exploitation for Client Execution, where adversaries will rely on macros being allowed or that the user will accept to activate them.

Many popular offensive frameworks exist which use forms of scripting for security testers and adversaries alike. Metasploit, Veil, and PowerSploit are three examples that are popular among penetration testers for exploit and post-compromise operations and include many features for evading defenses. Some adversaries are known to use PowerShell.

Tactics
Stealth · Execution
Platforms
Linux · macOS · Windows
Telemetry

chronicle/detection-rules

16 rules
Detection Severity Format
adwind_rat__jrat Undefined YARA-L
adwind_rat__jrat_part_1 Undefined YARA-L
adwind_rat__jrat_part_2 Undefined YARA-L
apt28_zekapabzebrocycannon_implant_sysmonfirewallproxy_part2 Undefined YARA-L
apt28_zekapab_zebrocy_implant__sysmon_firewall_proxy Undefined YARA-L
cactustorch_remote_thread_creation Undefined YARA-L
mshta_downloads_malware_by_using_covid19_themed_document Undefined YARA-L
nanocore_rat_loaded_by_covid19_update_xlsm_file Undefined YARA-L
powershell_obfuscation_by_agenttesla Undefined YARA-L
system_information_gathering_via_wmicexe Undefined YARA-L

+ 6 more from chronicle/detection-rules → showing the 10 highest-severity

socfortress/Wazuh-Rules

2 rules
Detection Severity Format
Sysmon - Event 11: FileCreate by · Scripting (T1064) Low Wazuh XML
Sysmon - Event 7: Image loaded by · Windows Scripting Host Component (T1064) Low Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.