wscript/cscript Executing Scripts from Temp or Downloads (T1059.005)
Detects the execution of script files (.vbs, .js, .wsf) using Windows script hosts (wscript.exe, cscript.exe) from common user-writable directories such as Temp, Downloads, and AppData. This behavior is often indicative of malicious files being dropped by phishing attachments or drive-by downloads and subsequently executed by an adversary.
SentinelOne

