Windows Attack Surface Management: Script-based Malware
ID: ff0f6679-587d-51c0-b0b4-bb8ff46f5ce7
STIX ID: report--ff0f6679-587d-51c0-b0b4-bb8ff46f5ce7
Feed Name: ReliaQuest Blog
Threat Score
This report examines the rising abuse of Windows scripting languages—PowerShell, JScript, and VBScript—by cybercriminals, explains why script-based attacks are effective (ubiquity, stealth, in-memory execution, access to .NET), cites observed usage and actor reliance (e.g., FIN7), and provides actionable mitigations and detection guidance such as Constrained Language Mode, restrictive execution policies, Windows Defender Exploit Guard, EDR, and monitoring rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
