Explorer-Initiated Remote HTA Execution via MSHTA
Detects mshta.exe launched from Windows Explorer to retrieve remote HTA content over HTTP, a technique frequently observed in phishing campaigns and initial access attacks.
Microsoft Sentinel (KQL)

Detects mshta.exe launched from Windows Explorer to retrieve remote HTA content over HTTP, a technique frequently observed in phishing campaigns and initial access attacks.

Already have an account?