Public Network MSHTA Activity from User Context
Identifies mshta.exe accessing externally hosted HTA content from a user-initiated Explorer session, potentially indicating malicious remote code execution.
Microsoft Sentinel (KQL)

Identifies mshta.exe accessing externally hosted HTA content from a user-initiated Explorer session, potentially indicating malicious remote code execution.

Already have an account?