Casbaneiro HTA Downloader via mshta.exe Loading .hta File
This rule detects the execution of mshta.exe with a command line referencing an HTA file, followed within 10 minutes by a network connection initiated by mshta.exe to a remote URL containing .js or .xml extensions. This behavior is indicative of mshta.exe being used as a proxy to execute remote malicious payloads, a common technique for fileless malware execution and defense evasion.
Microsoft Sentinel (KQL)

