1200KM / detection
T1059.007 JavaScript — Detection Rules
Detection workspace for T1059.007 JavaScript: 21 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Suspicious Installer Package Child Process · test · medium · {"category":"process_creation","product":"macos"}
- JXA In-memory Execution Via OSAScript · test · high · {"product":"macos","category":"process_creation"}
- Potential In-Memory Download And Compile Of Payloads · test · medium · {"category":"process_creation","product":"macos"}
- AppLocker Prevented Application or Script from Running · test · medium · {"product":"windows","service":"applocker"}
- HackTool - CACTUSTORCH Remote Thread Creation · test · high · {"product":"windows","category":"create_remote_thread"}
- Suspicious Deno File Written from Remote Source · experimental · low · {"category":"file_event","product":"windows"}
- WScript or CScript Dropper - File · test · high · {"category":"file_event","product":"windows"}
- Adwind RAT / JRAT File Artifact · test · high · {"category":"file_event","product":"windows"}
- Csc.EXE Execution Form Potentially Suspicious Parent · test · high · {"category":"process_creation","product":"windows"}
- HTML Help HH.EXE Suspicious Child Process · test · high · {"category":"process_creation","product":"windows"}
- Suspicious HH.EXE Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - Koadic Execution · test · high · {"category":"process_creation","product":"windows"}
- MSHTA Execution with Suspicious File Extensions · test · high · {"category":"process_creation","product":"windows"}
- Node Process Executions · test · medium · {"category":"process_creation","product":"windows"}
- NodeJS Execution of JavaScript File · experimental · low · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Inline JavaScript Execution via NodeJS Binary · experimental · medium · {"category":"process_creation","product":"windows"}
- Script Interpreter Spawning Credential Scanner - Windows · experimental · high · {"category":"process_creation","product":"windows"}
- Potential Remote SquiblyTwo Technique Execution · test · high · {"category":"process_creation","product":"windows"}
- XSL Script Execution Via WMIC.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Potential Dropper Script Execution Via WScript/CScript/MSHTA · test · medium · {"category":"process_creation","product":"windows"}
- Cscript/Wscript Uncommon Script Extension Execution · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1059.007 JavaScript
MATCH(script_host_execution) AND script_path IN temporary_or_user_writable_paths -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0264 Cross-Platform Detection of JavaScript Execution Abuse
AN0733 Analytic 0733
Detects JavaScript execution through WSH (wscript.exe, cscript.exe) or HTA (mshta.exe), particularly when spawned from Office macros, web browsers, or abnormal user paths. Correlates script execution with outbound network activity or system modification.
AN0734 Analytic 0734
Detects JavaScript for Automation (JXA) via osascript or compiled scripts using OSAKit APIs. Flags execution involving system modification, inter-process scripting, or browser abuse.
AN0735 Analytic 0735
Detects Node.js or JavaScript interpreter execution from web shells, cron jobs, or local users. Correlates execution with reverse shell behavior, file modifications, or abnormal outbound connections.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- Molerats · G0021
- FIN6 · G0037
- FIN7 · G0046
- APT32 · G0050
- MuddyWater · G0069
- Leafminer · G0077
- Cobalt Group · G0080
- Silence · G0091
- TA505 · G0092
- Kimsuky · G0094
- APT-C-36 · G0099
- Indrik Spider · G0119
- Evilnum · G0120
- Sidewinder · G0121
- Higaisa · G0126
- Mustang Panda · G0129
- LazyScripter · G0140
- Earth Lusca · G1006
- MoustachedBouncer · G1019
- Saint Bear · G1031
- Star Blizzard · G1033
- Winter Vivern · G1035
- TA577 · G1037
- TA578 · G1038
- Contagious Interview · G1052
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.