Suspicious VBScript Persistence in CurrentVersion Run Key

PremiumReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-10-05
Updated
2026-10-05

ATT&CK techniques

Execution → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects a CurrentVersion Run autorun value whose data references a script interpreter or inline VBScript, a persistence technique in which adversaries register a scripting payload to execute at logon. Storing wscript, mshta or vbscript logic in a Run key lets fileless or lightly obfuscated code survive reboots. Legitimate autorun entries rarely embed script keywords of this kind.

Related detections9 linkedT1059.005 — drag to rearrange
Suspicious SCMBanker Autostart Persistence via Run Key VBScript
Suspicious VBScript Code Stored in CurrentVersion Registry Value
Suspicious VBScript Payload Stored in CurrentVersion Registry Value (via registry_set)
Malicious Sibot Malware Registry Persistence Value
Suspicious Run Key Persistence in CurrentVersion (via registry_set)
Suspicious Run Key Persistence Referencing Script Files Linked to FIN7
Suspicious rundll32 or mshta Proxy Execution of VBScript
Suspicious Office Application Spawning Script Interpreter
Malicious rundll32 vbscript mshtml RunHTMLApplication Execution
Suspicious VBScript Persistence in CurrentVersion Run Key
Pivot detection · T1059.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.