kevmap

TechniquesT1059.007 › AN0733

AN0733 Analytic 0733

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects JavaScript execution through WSH (wscript.exe, cscript.exe) or HTA (mshta.exe), particularly when spawned from Office macros, web browsers, or abnormal user paths. Correlates script execution with outbound network activity or system modification.</p>
Detects
T1059.007 JavaScript
Part of
DET0264 Cross-Platform Detection of JavaScript Execution Abuse

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SysmonEventCode=1DC0032 Process Creation
m365:defenderScriptBlockLogging + AMSIDC0029 Script Execution
WinEventLog:SysmonEventCode=7DC0016 Module Load

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ParentProcessExecution of wscript.exe, cscript.exe, or mshta.exe from suspicious parent like Excel or Outlook.
ScriptPathScript loaded from %TEMP%, user download folder, or via UNC/web path.
TimeWindowExecution of JavaScript during non-business or patch windows.
UserContextExecution by accounts not typically authorized for scripting (e.g., non-admin users).
EntropyScoreObfuscated JS with high entropy detected by AMSI or ScriptBlock logging.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2013-3346Adobe Reader and AcrobatMapped
CVE-2015-5119Adobe Flash PlayerMapped
CVE-2018-4990Adobe Acrobat and ReaderMapped
CVE-2021-21148Google Chromium V8Mapped
CVE-2021-21166Google ChromiumMapped
CVE-2021-21206Google Chromium BlinkMapped
CVE-2021-30554Google Chromium WebGLMapped
CVE-2021-37975Google Chromium V8Mapped
CVE-2022-22963VMware Tanzu Spring CloudMapped
CVE-2022-24682Synacor Zimbra Collaborate Suite (ZCS)Mapped
CVE-2023-22515Atlassian Confluence Data Center and ServerMapped
CVE-2023-26360Adobe ColdFusionMapped
CVE-2023-5631Roundcube WebmailMapped
CVE-2025-34028Commvault Command CenterMapped