Windows Process Creation: mshta/VBScript Launching PowerShell and Embedded Backdoor Logic

Alerts on Windows command lines combining mshta VBScript execution bypass, system survey WMI queries, and PowerShell HTTP/Base64 patterns.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-03-10
Updated
2026-07-31

What it detects

This rule flags Windows process creation events where the command line matches an mshta/VBScript pattern that invokes PowerShell with execution bypass and writes activity under the ProgramData directory. It also looks for follow-on discovery/backdoor indicators in the same command line, including WMI queries for system and network information and encoded payload handling using .NET Base64/UTF-8 and HTTP response streaming with HTTPWebRequest. This matters because such behaviors are commonly used to execute and stage malicious payloads while minimizing user visibility; detection relies on process creation telemetry with full command-line capture.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.