Windows Script Host Execution with Parent Process Masking
This rule detects the execution of Windows Script Host (wscript.exe or cscript.exe) where the initiating parent process is not a common legitimate process like explorer.exe, cmd.exe, powershell.exe, svchost.exe, or system.exe, and is also not a web browser (Chrome or Firefox). This pattern can indicate an attempt to execute malicious VBScript or JScript files, potentially delivered via phishing, where the script is launched by an unusual or obfuscated parent process to evade detection.
Microsoft Sentinel (KQL)

