1200KM / detection
T1220 XSL Script Processing — Detection Rules
Detection workspace for T1220 XSL Script Processing: 5 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- WMIC Loading Scripting Libraries · test · medium · {"category":"image_load","product":"windows"}
- Msxsl.EXE Execution · test · medium · {"category":"process_creation","product":"windows"}
- Remote XSL Execution Via Msxsl.EXE · test · high · {"category":"process_creation","product":"windows"}
- Potential Remote SquiblyTwo Technique Execution · test · high · {"category":"process_creation","product":"windows"}
- XSL Script Execution Via WMIC.EXE · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0205 Detect XSL Script Abuse via msxsl and wmic
AN0581 Analytic 0581
Execution of XSL scripts via msxsl.exe or wmic.exe using embedded JScript or VBScript for proxy execution. Detection correlates process creation, command-line patterns, and module load behavior of scripting components (e.g., jscript.dll).
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.