T1059.005Visual Basic
T1059.005 — Visual Basic is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 16 detection use cases covering it and 121 threat-intel articles citing it.
Execution
16Use cases
121Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1059 · Command and Scripting Interpreter
Use cases covering this technique (16)
Office app spawning script/LOLBin child process Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI Cisco NVM - Susp Script From Archive Triggering Network Activity Execute Javascript With Jscript COM CLSID Vbscript Execution Using Wscript App Windows Outlook Macro Created by Suspicious Process Suspicious Process DNS Query Known Abuse Web Services Suspicious Process With Discord DNS Query [LLM] SHEETCORD VBS Startup-folder persistence drop [LLM] Gamaredon HTA downloader auto-executing from Startup folder at logon (mshta.exe) [LLM] Gamaredon stealer exfiltration to S3-compatible cloud storage (Wasabi/Tebi/Intercolo) [LLM] axios RAT Windows payload drop (6202033.vbs/.ps1, ProgramData\wt) during npm install [LLM] axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging [LLM] cscript/wscript executing a script from .laravel_locale temp directory [LLM] cscript.exe launching .vbs from .laravel_locale temp directory [LLM] PowerShell masquerading as Windows Terminal at %PROGRAMDATA%\wt.exe (Axios RAT Windows stage)Articles citing this technique (121)
crit ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories art-51
high Curiouser and Curiouser art-52
crit AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS art-55
high Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection art-91
crit Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS art-101
crit Begun, the Patch Wars have art-253
crit ESET Threat Report H1 2026 art-312
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-448
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-673
crit ESET Threat Report H2 2025 art-762
crit CISA KEV: CVE-2024-38226 — Microsoft Publisher Protection Mechanism Failure Vulnerability art-1253
high Defense in Depth art-1415
high Ethical hacking techniques art-1721
high Ethical Hacking: Top Tools art-1725
crit API Security Guide art-1774
high Securing the web (forward) art-1826
high Cybersecurity Hygiene 101 art-1847
crit Secure Python URL validation art-1960
high Securing PHP containers art-2105
crit CISA KEV: CVE-2014-6287 — Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability art-2461
med Python Poetry package manager and security integration with software composition analysis tool art-3283
crit XSS Attacks: The Next Wave art-3664
high A CEO's guide to Emacs art-3716