Windows: PowerShell-triggered HTA retrieval and execution with registry and process disruption

Alerts on Windows process creation where PowerShell uses mshta over HTTP and includes .hta, registry query, and cmd.exe termination.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2019-02-24
Updated
2026-07-31

ATT&CK techniques

Execution → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows process creation where a PowerShell command line indicates downloading and executing an HTA payload via mshta.exe from an HTTP URL. It also requires additional suspicious command-line components, including registry querying related to Terminal Server Client defaults, uploading a remote file using .NET WebClient, and terminating cmd.exe. Such behavior can align with staged malware delivery and execution, relying on process creation telemetry with full command-line visibility.

Related detections9 linkedT1059.001 — drag to rearrange
Malicious Forfiles Proxy Execution Launching PowerShell and MSHTA in PEAKLIGHT Chain (via process_creation)
Malicious ClickFix PowerShell Launching mshta with Remote URL (via process_creation)
MSSQL Server Process Spawning Command Shell via xp_cmdshell
Suspicious PowerShell Query of MSHTA Application Class in PEAKLIGHT Chain (via ps_script)
Suspicious MSSQL xp_cmdshell OS Command Execution via sqlservr.exe (via process_creation)
Malicious Fire Ant Host-to-Guest Command Execution via VMware Tools (via process_creation)
Malicious Office Application Spawning a Command Shell or Script Interpreter (via process_creation)
Malicious PowerShell or Command Shell Spawned by SQL Server via xp_cmdshell
Windows AppLocker Audit-Mode Events Indicate Files Would Have Been Blocked
Windows: PowerShell-triggered HTA retrieval and execution with registry and process disruption
Pivot detection · T1059.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.