Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1218.005

T1218.005Mshta

T1218.005 — Mshta is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 19 detection use cases covering it and 5 threat-intel articles citing it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
19Use cases
5Articles
0Sub-techniques
1Tactic

Use cases covering this technique (19)

[WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI ESCU actions · hunting P Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download ESCU actions · hunting P Detect mshta inline hta execution ESCU actions · alerting P Detect mshta renamed ESCU actions · hunting P Detect MSHTA Url in Command Line ESCU actions · alerting P Detect Rundll32 Inline HTA Execution ESCU actions · alerting P Mshta spawning Rundll32 OR Regsvr32 Process ESCU actions · alerting P Suspicious mshta child process ESCU actions · alerting P Suspicious mshta spawn ESCU actions · alerting P Windows Mshta Execution In Registry ESCU actions · alerting P Windows MSHTA Writing to World Writable Path ESCU actions · alerting P Windows Process Writing File to World Writable Path ESCU actions · hunting P [LLM] mshta.exe outbound connection to public host (remote HTA C2 retrieval) Bespoke c2 · hunting DSΣPDDCS [LLM] mshta.exe launched with inline http/https URL argument Bespoke delivery · alerting DSΣPDDCS [LLM] mshta.exe spawning command interpreter or secondary LOLBin Bespoke exploit · alerting DSΣPDDCS [LLM] ClickFix mshta.exe silently executing remote HTA then dropping batch (UAT-11795 initial access) Bespoke delivery · alerting DSΣPDDCS [LLM] mshta.exe HTA downloader reaching UAT-11795 staging domains (ClickFix) Bespoke delivery · alerting DSΣPDDCS [LLM] Gamaredon HTA downloader auto-executing from Startup folder at logon (mshta.exe) Bespoke exploit · alerting DSΣPDDCS

Articles citing this technique (5)