WScript/CScript Executing Scripts from Suspicious Directories
Detects the execution of Windows Script Host (wscript.exe or cscript.exe) to run script files (.vbs, .js, .wsf, .hta) located in commonly abused writable directories such as Temp, AppData, Downloads, or ProgramData. This behavior is indicative of a malicious actor executing scripts that have been dropped onto the system as part of a phishing campaign or other attack vector.
SentinelOne

