SocGholish Browser ZIP Download Followed by wscript/mshta Execution
This rule detects scenarios where a common web browser (Chrome, Firefox, Edge, IE, Opera, or Brave) connects to an external destination not on a known allow-list, followed shortly (within 30 seconds) by the execution of a script-based binary (wscript.exe or mshta.exe) on the same host. This is a common pattern for initial access where a user downloads a malicious script from an unknown source via a browser and subsequently executes it.
Splunk (SPL)

