HEAVYGRAM WSF/VBS PowerShell Cradle Downloading from Vultr Object Storage
Detects potentially malicious script execution patterns, specifically targeting Windows Script Host (wscript.exe) invoking .vbs or .wsf files, and PowerShell execution involving suspicious command line arguments such as encoding (-enc), external URL downloading, or attempts to execute or archive files (Expand-Archive, WebClient DownloadFile).
CQL

