1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1059.007 JavaScript — Detection Rules

Detection workspace for T1059.007 JavaScript: 21 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

T1059.007 JavaScript

MATCH(script_host_execution) AND script_path IN temporary_or_user_writable_paths -> ALERT

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0264 Cross-Platform Detection of JavaScript Execution Abuse

AN0733 Analytic 0733

Detects JavaScript execution through WSH (wscript.exe, cscript.exe) or HTA (mshta.exe), particularly when spawned from Office macros, web browsers, or abnormal user paths. Correlates script execution with outbound network activity or system modification.

AN0734 Analytic 0734

Detects JavaScript for Automation (JXA) via osascript or compiled scripts using OSAKit APIs. Flags execution involving system modification, inter-process scripting, or browser abuse.

AN0735 Analytic 0735

Detects Node.js or JavaScript interpreter execution from web shells, cron jobs, or local users. Correlates execution with reverse shell behavior, file modifications, or abnormal outbound connections.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1059.007 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.