Suspicious Windows Process Execution of gatherNetworkInfo.vbs via Cscript/Wscript
Alerts on Windows executions referencing gatherNetworkInfo.vbs in process command lines, indicative of potential discovery activity.
- Product
- windows
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-02-08
- Updated
- 2026-07-30
ATT&CK techniques
Execution → DiscoveryRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process creation where the command line contains the built-in script path component "gatherNetworkInfo.vbs". Attackers may use this script to collect host/network information during reconnaissance. It relies on Windows process creation telemetry, correlating command-line content with the script identifier while excluding cases where cscript.exe or wscript.exe are the parent image.
Reporting behind it
- posts.slayerlabs.comhttps://posts.slayerlabs.com/living-off-the-land/#gathernetworkinfovbs
- mandiant.comhttps://www.mandiant.com/resources/blog/trojanized-windows-installers-ukrainian-government
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_gather_network_info_execution.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Suspicious Windows Process Execution of gatherNetworkInfo.vbs via Cscript/Wscript
id: dfa6da87-821e-4df8-8180-332d1b1458ba
related:
- id: f92a6f1e-a512-4a15-9735-da09e78d7273
type: similar
- id: 575dce0c-8139-4e30-9295-1ee75969f7fe
type: similar
- id: 07aa184a-870d-413d-893a-157f317f6f58
type: derived
status: test
description: This rule flags process creation where the command line contains the built-in script path component "gatherNetworkInfo.vbs". Attackers may use this script to collect host/network information during reconnaissance. It relies on Windows process creation telemetry, correlating command-line content with the script identifier while excluding cases where cscript.exe or wscript.exe are the parent image.
references:
- https://posts.slayerlabs.com/living-off-the-land/#gathernetworkinfovbs
- https://www.mandiant.com/resources/blog/trojanized-windows-installers-ukrainian-government
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_gather_network_info_execution.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-02-08
tags:
- attack.discovery
- attack.execution
- attack.t1615
- attack.t1059.005
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains: gatherNetworkInfo.vbs
filter:
Image|endswith:
- \cscript.exe
- \wscript.exe
condition: selection and not filter
falsepositives:
- Unknown
level: high
license: DRL-1.1