Malicious Mshta Spawned by WMI or WinRM Provider via process_creation

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-08
Updated
2026-10-08

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects mshta.exe launched by the WMI provider host or the WinRM host process which indicates remote or lateral proxy execution of an HTA payload. GOFFEE triggered mshta.exe from wmiprvse.exe and wsmprovhost.exe to run remote HTA content while blending with management traffic. This parent child relationship is abnormal and points to hands-on remote code execution.

Related detections9 linkedT1218.005 — drag to rearrange
Suspicious mshta.exe Executing Remote Media-Extension URL
Suspicious mshta.exe Executing Embedded JavaScript from LNK Chain (via process_creation)
Suspicious VBScript Code Stored in CurrentVersion Registry Value
Suspicious rundll32 or mshta Proxy Execution of VBScript
Suspicious mshta Execution of Remote or Inline Payload (via process_creation)
Suspicious mshta Execution Proxied Through pcalua LOLBIN
Suspicious mshta Downloading Remote Payload via ClickFix
Malicious mshta Spawning PowerShell Loader via ClickFix
Suspicious Remote HTA Execution via mshta over HTTP
Malicious Mshta Spawned by WMI or WinRM Provider via process_creation
Pivot detection · T1218.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.