Windows Process Command Line: Suspicious Inline VBScript with UN2452-Like Keywords

Alerts on Windows command lines containing inline VBScript keywords and registry access indicators matching the UNC2452 UN2452 pattern.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2021-03-05
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows process creations whose command lines contain a set of inline VBScript keywords commonly associated with UNC2452-style scripting behavior. The combination of VBScript execution, object creation, registry reading, and window-closing patterns can indicate automated script-driven persistence or privilege-related activity. It relies on process creation telemetry, specifically the full CommandLine content and a negative match excluding startup Run key paths.

Related detections9 linkedT1547.001 — drag to rearrange
Malicious axios NPM Supply Chain Persistence via MicrosoftUpdate Run Key
Malicious Registry Run Key Persistence Masquerading as MicrosoftUpdate
Malicious Run Key Persistence Referencing DLL in User Documents
PlugX Persistence via Run Key Named AAM Updatevlm
Suspicious Autorun Registry Persistence via sausageLoop Run Key
Malicious BabyLockerKZ Run Key Persistence
Suspicious Run Key Persistence Pointing To User-Writable Path
Malicious Ctrlpanel Run Key Autostart Persistence (via registry_set)
Persistence Run Key Pointing to svchost.exe in AppData Roaming
Windows Process Command Line: Suspicious Inline VBScript with UN2452-Like Keywords
Pivot detection · T1547.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.