Robuta

Sponsor of the Day: Jerkmate
https://docs.chocolatey.org/en-us/community-repository/moderation/package-validator/rules/cpmr0063/ Chocolatey Software Docs | CPMR0063 - Usage of WScript (script) Information on how to remediate the Chocolatey Package Moderation Rule 0063 chocolatey software docsusagewscript https://detection.fyi/sigmahq/sigma/windows/process_creation/proc_creation_win_wscript_cscript_dropper/ Potential Dropper Script Execution Via WScript/CScript | Detection.FYI Detects wscript/cscript executions of scripts located in user directories script executiondetection fyipotentialdroppervia https://detection.fyi/sigmahq/sigma/windows/process_creation/proc_creation_win_wscript_cscript_susp_child_processes/ Cscript/Wscript Potentially Suspicious Child Process | Detection.FYI Detects potentially suspicious child processes of Wscript/Cscript. These include processes such as rundll32 with uncommon exports or PowerShell spawning … potentially suspicious childprocess detection fyiwscript