Mshta.exe launched with suspicious arguments
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
LOLBIN Execution Analytics
ATT&CK Tactic
Stealth (TA0005)
ATT&CK Technique
System Binary Proxy Execution: Mshta (T1218.005)
Severity
Low
Description
Microsoft HTML application host process has been launched with suspicious arguments, which may indicate malicious intent.
Attacker's Goals
Gain code execution on the host and evade security controls.
Investigative actions
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
PreviousMpCmdRun.exe was used to download files into the system
NextMshta.exe spawns from a browser process
Was this helpful?
