Mshta.exe Executing Remote or Inline Script via javascript/vbscript/HTTP (T1218.005)
Detects the execution of mshta.exe with suspicious command-line arguments, including the use of 'javascript:', 'vbscript:', or HTTP/HTTPS URLs. These patterns are commonly used to proxy the execution of malicious HTML Applications (HTA) or scripts to bypass security controls. The rule includes an exclusion for legitimate Microsoft-signed mshta.exe processes that do not contain these suspicious indicators.
SentinelOne

