T1059.005 Visual Basic
Sub-technique of T1059 Command and Scripting Interpreter
Adversaries may abuse Visual Basic (VB) for execution. VB is a programming language created by Microsoft with interoperability with many Windows technologies such as [Component Object Model](https://attack.mitre.org/techniques/T1559/001) and the [Native API](https://attack.mitre.org/techniques/T1106) through the Windows API. Although tagged as legacy with no planned future evolutions, VB is…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Potential QBot Activitycriticalstable · windows
- Adwind RAT / JRAThightest · windows
- Adwind RAT / JRAT File Artifacthightest · windows
- Csc.EXE Execution Form Potentially Suspicious Parenthightest · windows
- Cscript/Wscript Uncommon Script Extension Executionhightest · windows
- HTML Help HH.EXE Suspicious Child Processhightest · windows
- HackTool - CACTUSTORCH Remote Thread Creationhightest · windows
- HackTool - Koadic Executionhightest · windows
- Potential APT10 Cloud Hopper Activityhightest · windows
- Potential Remote SquiblyTwo Technique Executionhightest · windows
- Suspicious Child Process Of BgInfo.EXEhightest · windows
- Suspicious HH.EXE Executionhightest · windows
- Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBShightest · windows
- Suspicious Scripting in a WMI Consumerhightest · windows
- WScript or CScript Dropper - Filehightest · windows
- Windows Shell/Scripting Processes Spawning Suspicious Programshightest · windows
- Axios NPM Compromise Indicators - Windowshighexperimental · windows
- HackTool - NetExec File Indicatorshighexperimental · windows
- AppLocker Prevented Application or Script from Runningmediumtest · windows
- Potential Dropper Script Execution Via WScript/CScript/MSHTAmediumtest · windows
- Potential Reconnaissance Activity Via GatherNetworkInfo.VBSmediumtest · windows
- Uncommon Child Process Of BgInfo.EXEmediumtest · windows
- XSL Script Execution Via WMIC.EXEmediumtest · windows
- AppLocker Application Would Have Been Blockedmediumexperimental · windows
- MMC Loading Script Engines DLLsmediumexperimental · windows
Showing 25 of 28.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.