Commonly abused AutoIT script drops an executable file to disk
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
Command and Scripting Interpreter: AutoHotKey & AutoIT (T1059.010), Command and Scripting Interpreter: Windows Command Shell (T1059.003)
Severity
Informational
Description
AutoIT scripts have legitimate uses but are often abused by malware to execute in a signed process context.
Attacker's Goals
Gain code execution on the host and evade security controls.
Investigative actions
Check whether the command line executed is benign or normal for the host and/or user performing it.
Check whether the user from the command line is an administrator or other sensitive account.
Was this helpful?
