Sponsor of the Day:
Jerkmate
https://docs.chocolatey.org/en-us/community-repository/moderation/package-validator/rules/cpmr0063/
Chocolatey Software Docs | CPMR0063 - Usage of WScript (script)
Information on how to remediate the Chocolatey Package Moderation Rule 0063
chocolatey software docsusagewscript
https://detection.fyi/sigmahq/sigma/windows/process_creation/proc_creation_win_wscript_cscript_dropper/
Potential Dropper Script Execution Via WScript/CScript | Detection.FYI
Detects wscript/cscript executions of scripts located in user directories
script executiondetection fyipotentialdroppervia
https://detection.fyi/sigmahq/sigma/windows/process_creation/proc_creation_win_wscript_cscript_susp_child_processes/
Cscript/Wscript Potentially Suspicious Child Process | Detection.FYI
Detects potentially suspicious child processes of Wscript/Cscript. These include processes such as rundll32 with uncommon exports or PowerShell spawning …
potentially suspicious childprocess detection fyiwscript