Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Execution/ T1059.005

T1059.005Visual Basic

T1059.005 — Visual Basic is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 18 detection use cases covering it and 155 threat-intel articles citing it.

Execution
View on the matrix → Filter Detection Library MITRE official spec ↗
18Use cases
155Articles
0Sub-techniques
1Tactic

Use cases covering this technique (18)

Office app spawning script/LOLBin child process Internal exploit · alerting DSΣP Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI ESCU actions · hunting P Cisco NVM - Susp Script From Archive Triggering Network Activity ESCU actions · hunting P Execute Javascript With Jscript COM CLSID ESCU actions · alerting P Vbscript Execution Using Wscript App ESCU actions · alerting P Windows Outlook Macro Created by Suspicious Process ESCU actions · alerting P Suspicious Process DNS Query Known Abuse Web Services ESCU actions · alerting P Suspicious Process With Discord DNS Query ESCU actions · hunting P [LLM] ClickFix PowerShell loader spawning wscript to run downloaded VBScript Bespoke exploit · alerting DSΣPDDCS [LLM] BusySnake VBScript persistence: wh_selfdelete.vbs / run.vbs in WindowsHelper Bespoke install · alerting DSΣPDDCS [LLM] Gamaredon HTA downloader auto-executing from Startup folder at logon (mshta.exe) Bespoke exploit · alerting DSΣPDDCS [LLM] Gamaredon stealer exfiltration to S3-compatible cloud storage (Wasabi/Tebi/Intercolo) Bespoke actions · alerting DSΣPDDCS [LLM] axios RAT Windows payload drop (6202033.vbs/.ps1, ProgramData\wt) during npm install Bespoke install · alerting DSΣPDDCS [LLM] axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging Bespoke install · alerting DSΣPDDCS [LLM] cscript/wscript executing a script from .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] cscript.exe launching .vbs from .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] PowerShell masquerading as Windows Terminal at %PROGRAMDATA%\wt.exe (Axios RAT Windows stage) Bespoke install · alerting DSΣPDDCS [LLM] PowerShell copy masqueraded as Windows Terminal in %PROGRAMDATA% running 6202033.ps1 Bespoke install · alerting DSΣPDD

Articles citing this technique (155)