VBScript Loading WinHTTP Objects for C2 Communication
This rule detects VBScript execution (via wscript.exe or cscript.exe) that attempts to load WinHTTP objects (WinHttpRequest.5.1, MSXML2.XMLHTTP) or uses generic object creation functions (CreateObject, GetObject). This behavior is often associated with VBScripts establishing command and control (C2) communication or performing data exfiltration.
Microsoft Sentinel (KQL)

