Malicious Fileless JavaScript Execution via Deno Data URI (via process_creation)

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-06-07
Updated
2026-08-28

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the Deno runtime executing an inline base64 encoded JavaScript payload passed as a data application javascript URI, a fileless execution technique used by attackers abusing alternative runtime environments to evade disk based detection. The allow all flag combined with an inline data URI is a strong indicator of malicious in memory code execution.

Related detections9 linkedT1027 — drag to rearrange
Possible React2Shell CVE-2025-55182 Prototype Pollution Exploitation
Suspicious Node.js Script Execution from AppData Roaming
Possible Reflected XSS via cPanel cpanelwebcall Endpoint CVE-2023-29489
Malicious Non-Interactive Encoded PowerShell Stager (via process_creation)
Suspicious Hidden PowerShell Executing Substring of Dropped File
SocGholish Fake Browser Update Script Execution (via process_creation)
PowerShell Encoded or Download-Cradle Command Line (via process_creation)
Obfuscated Encoded PowerShell Payload Deployed via Process Execution (via process_creation)
Obfuscated Encoded PowerShell Payload Deployed - PowerShell (via powershell)
Malicious Fileless JavaScript Execution via Deno Data URI (via process_creation)
Pivot detection · T1027 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.