Most Popular LOLBAS 2026: Mshta Executing Remote HTA or JavaScript Payload
Detects the execution of the Windows built-in utility mshta.exe when it is used to load remote HTA files or scripts via HTTP/HTTPS URLs, or when it is directly spawned by Microsoft Office applications (Word/Excel). This behavior is characteristic of malicious document macros or phishing-based initial access where mshta is used as a proxy to execute code and evade security controls.
Sigma

