1200KM / detection
T1059.005 Visual Basic — Detection Rules
Detection workspace for T1059.005 Visual Basic: 23 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- AppLocker Prevented Application or Script from Running · test · medium · {"product":"windows","service":"applocker"}
- HackTool - CACTUSTORCH Remote Thread Creation · test · high · {"product":"windows","category":"create_remote_thread"}
- WScript or CScript Dropper - File · test · high · {"category":"file_event","product":"windows"}
- HackTool - NetExec File Indicators · experimental · high · {"product":"windows","category":"file_event"}
- Adwind RAT / JRAT File Artifact · test · high · {"category":"file_event","product":"windows"}
- MMC Loading Script Engines DLLs · experimental · medium · {"category":"image_load","product":"windows"}
- Registry Modification Attempt Via VBScript - PowerShell · experimental · medium · {"category":"ps_script","product":"windows"}
- Suspicious Child Process Of BgInfo.EXE · test · high · {"category":"process_creation","product":"windows"}
- Uncommon Child Process Of BgInfo.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Csc.EXE Execution Form Potentially Suspicious Parent · test · high · {"category":"process_creation","product":"windows"}
- HTML Help HH.EXE Suspicious Child Process · test · high · {"category":"process_creation","product":"windows"}
- Suspicious HH.EXE Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - Koadic Execution · test · high · {"category":"process_creation","product":"windows"}
- Potential Reconnaissance Activity Via GatherNetworkInfo.VBS · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBS · test · high · {"category":"process_creation","product":"windows"}
- Windows Shell/Scripting Processes Spawning Suspicious Programs · test · high · {"category":"process_creation","product":"windows"}
- Registry Modification Attempt Via VBScript · experimental · medium · {"category":"process_creation","product":"windows"}
- Potential Remote SquiblyTwo Technique Execution · test · high · {"category":"process_creation","product":"windows"}
- XSL Script Execution Via WMIC.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Potential Dropper Script Execution Via WScript/CScript/MSHTA · test · medium · {"category":"process_creation","product":"windows"}
- Cscript/Wscript Uncommon Script Extension Execution · test · high · {"category":"process_creation","product":"windows"}
- Registry Tampering by Potentially Suspicious Processes · experimental · medium · {"category":"registry_event","product":"windows"}
- Suspicious Scripting in a WMI Consumer · test · high · {"product":"windows","category":"wmi_event"}
Atlas deterministic concepts
T1059.005 Visual Basic
MATCH(process_name IN [cscript.exe, wscript.exe]) AND script_path NOT_IN approved_script_paths -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0076 Behavioral Detection of Visual Basic Execution (VBS/VBA/VBScript)
AN0209 Analytic 0209
Detects execution of VB-based scripts or macros (VBS/VBA/VBScript) through cscript.exe/wscript.exe, Office-based process chains, or HTA usage. Focuses on chained behavior: Office or HTML container spawns script host > script host spawns PowerShell, network connections, or process injection.
AN0210 Analytic 0210
Detects embedded or emulated VBScript/VBA execution via Wine-based apps, Office for Mac abusing cross-platform .NET features, or macros dropped and invoked via AppleScript or third-party automation tools.
AN0211 Analytic 0211
Detects abuse of Mono/.NET Core environments to execute VB-like scripts, often in environments with Office emulation or WINE. Focus is on rare invocations of scripting hosts like mono.exe or .NET shells, often seen in spam filtering or forensic labs with Office support.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- Molerats · G0021
- Lazarus Group · G0032
- Sandworm Team · G0034
- Patchwork · G0040
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- TA459 · G0062
- APT33 · G0064
- Leviathan · G0065
- APT37 · G0067
- MuddyWater · G0069
- Rancor · G0075
- Gorgon Group · G0078
- Cobalt Group · G0080
- APT38 · G0082
- FIN4 · G0085
- APT39 · G0087
- WIRTE · G0090
- Silence · G0091
- TA505 · G0092
- Kimsuky · G0094
- Machete · G0095
- APT-C-36 · G0099
- Inception · G0100
- Windshift · G0112
- Sidewinder · G0121
- Higaisa · G0126
- Mustang Panda · G0129
- Transparent Tribe · G0134
- LazyScripter · G0140
- Confucius · G0142
- HEXANE · G1001
- Earth Lusca · G1006
- SideCopy · G1008
- FIN13 · G1016
- TA2541 · G1018
- Malteiro · G1026
- RedCurl · G1039
- APT42 · G1044
- Contagious Interview · G1052
- MirrorFace · G1054
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.