logo

Windows Attack Surface Management: Script-based Malware

ID: ff0f6679-587d-51c0-b0b4-bb8ff46f5ce7

STIX ID: report--ff0f6679-587d-51c0-b0b4-bb8ff46f5ce7

Feed Name: ReliaQuest Blog

Threat Score
65/100

Date Published: 2024-06-04

Date Updated: 2026-04-29

...
...

This report examines the rising abuse of Windows scripting languages—PowerShell, JScript, and VBScript—by cybercriminals, explains why script-based attacks are effective (ubiquity, stealth, in-memory execution, access to .NET), cites observed usage and actor reliance (e.g., FIN7), and provides actionable mitigations and detection guidance such as Constrained Language Mode, restrictive execution policies, Windows Defender Exploit Guard, EDR, and monitoring rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.