Windows mshta.exe Execution Using Non-HTA File Extensions

Alerts on mshta.exe launched with command-line indicators for suspicious non-HTA file types and VBScript.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Diego Perez (@darkquassar), Markus Neis, Swisscom (Improve Rule), Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2019-02-22
Updated
2026-07-30

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags process execution of mshta.exe when the command line references file extensions and related content indicators that do not commonly represent HTML Application (HTA) inputs. Attackers may abuse this legitimate Windows utility to load malicious scripts disguised as benign files or served under misleading extensions to evade other detections. The detection relies on Windows process creation telemetry, matching mshta.exe and scanning the command line for a list of suspicious extensions and the string vbscript.

Related detections9 linkedT1059.007 — drag to rearrange
Windows: Alert on suspicious parent process spawning csc.exe
Windows Remote Thread Creation via CACTUSTORCH Using Script/Office/Rundll Host Images
Suspicious Shell Command Obfuscation via printf Escape Encoding on VMware ESXi (via process_creation)
Suspicious MSHTA Execution Spawned by Browser or Document Reader via Mispadu (via process_creation)
Suspicious npm Postinstall Node Execution From Fixtures Path (BeaverTail OtterCookie)
Suspicious Script Host Execution of Decoy-Named JavaScript Dropper (PS1Bot)
Malicious Emmenhtal JavaScript Loader Spawning Encoded PowerShell
Suspicious Office Application Spawning Mshta With Remote HTA
Suspicious Script Host Spawning PowerShell With Bypass And Hidden Execution
Windows mshta.exe Execution Using Non-HTA File Extensions
Pivot detection · T1059.007 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.