For the complete documentation index, see llms.txt. This page is also available as Markdown.

Commonly abused AutoIT script connects to an external domain

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Exfiltration (TA0010), Execution (TA0002)

ATT&CK Technique

Command and Scripting Interpreter: AutoHotKey & AutoIT (T1059.010), Automated Exfiltration (T1020)

Severity

Medium

Description

AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context.

Attacker's Goals

Communicate with malware running on your network to control malware activities, perform software updates on the malware, or to take inventory of infected machines.

Investigative actions

  • AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context.

  • Identify the process contacting the remote domain and determine whether the traffic is malicious.

Was this helpful?