Skip to content

Latest commit

 

History

History
47 lines (40 loc) · 2.12 KB

LEGACY-S00165.md

File metadata and controls

47 lines (40 loc) · 2.12 KB

Rules: VBS file downloaded from Internet

Description

Although Visual Basic scripts (.vbs) are sometimes regularly downloaded from the Internet, they are often part of malware establishment. They carry an elevated risk.

Additional Details

Detail Value
Type Match
Category Execution
Apply Risk to Entities device_hostname, device_ip, srcDevice_hostname, srcDevice_ip, user_username
Signal Name VBS file downloaded from Internet
Summary Expression User: {{user_username}} download VBS file on IP: {{srcDevice_ip}} from URL: {{http_url}}
Score/Severity Static: 3
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0002, _mitreAttackTechnique:T1204, _mitreAttackTechnique:T1204.002, _mitreAttackTechnique:T1059, _mitreAttackTechnique:T1059.005

Vendors and Products

Fields Used

Origin Field
Normalized Schema device_hostname
Normalized Schema device_ip
Normalized Schema dstDevice_ip_isInternal
Normalized Schema http_url
Normalized Schema http_url_alexaRank
Normalized Schema listMatches
Normalized Schema srcDevice_hostname
Normalized Schema srcDevice_ip
Normalized Schema user_username