Elastic medium stable eql
Mshta Making Network Connections
Identifies Mshta.exe making outbound network connections. This may indicate adversarial activity, as Mshta is often leveraged by adversaries to execute malicious scripts and evade detection.
Detection Logic
sequence by process.entity_id with maxspan=10m
[process where host.os.type == "windows" and event.type == "start" and process.name : "mshta.exe" and
not process.parent.name : "Microsoft.ConfigurationManagement.exe" and
not (process.parent.executable : "C:\\Amazon\\Amazon Assistant\\amazonAssistantService.exe" or
process.parent.executable : "C:\\TeamViewer\\TeamViewer.exe") and
not process.args : "ADSelfService_Enroll.hta"]
[network where host.os.type == "windows" and process.name : "mshta.exe"] Field Validations
Loading…
Comments (0)
Loading comments...