Suspicious AutoIt Interpreter Launched by Script Host or Shell

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-25
Updated
2026-09-25

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the AutoIt3 interpreter being launched by PowerShell or a command shell, a delivery pattern observed in Operation Poseidon where a ZIP to LNK to PowerShell chain executed AutoIt3.exe to load the EndRAT payload in memory. It captures abuse of the legitimate AutoIt engine to run compiled malicious scripts. Detecting this parentage is important because AutoIt3 spawned by a scripting host rather than a user-launched application is a common malware loader pattern.

Related detections9 linkedT1059.001 — drag to rearrange
Windows PowerShell Base64-encoded shellcode in ScriptBlockText
Suspicious PowerShell Spawned by WScript With Hidden Bypass via PureLogs Loader (via process_creation)
Suspicious PowerShell Execution of TrainedDataStore Script
Suspicious Salamander Named Pipe Creation
Suspicious Archive Expansion into Public User Directory via PowerShell (via ps_script)
Suspicious ClickFix PowerShell Download Cradle via TAG-150 Tradecraft
Malicious PowerShell Download of FortiEndpoint Patch Masquerade via EKZ Stealer
Suspicious Delayed Expansion Command Obfuscation Building PowerShell via Amatera Stealer
Suspicious PowerShell Host and Locale Reconnaissance via MuddyWater Tsundere Botnet
Suspicious AutoIt Interpreter Launched by Script Host or Shell
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.