Detection Playbook: Visual Basic (T1059.005)

T1059.005 · 2026-06-17 Visual Basic Execution Linux macOS Windows MITRE ATT&CK → Technique Visual Basic (T1059.005) Tactic Execution Platforms Linux, macOS, Windows Overview Visual Basic (VB) and its derivatives — Visual Basic for Applications (VBA) and VBScript — are scripting and programming languages that adversaries abuse to execute malicious code on target systems. Attackers commonly … Read more

Detection Playbook: Scheduled Task (T1053.005)

T1053.005 · 2026-06-16 Scheduled Task Execution Windows MITRE ATT&CK → Technique Scheduled Task (T1053.005) Tactic Execution Platforms Windows Overview Windows Scheduled Tasks (T1053.005) allow adversaries to register code to run automatically at a specified time, interval, or system event. Attackers use this capability to achieve persistence across reboots, execute payloads under elevated contexts such as … Read more

Detection Playbook: Windows Management Instrumentation (T1047)

T1047 · 2026-06-15 Windows Management Instrumentation Execution Windows MITRE ATT&CK → Technique Windows Management Instrumentation (T1047) Tactic Execution Platforms Windows Overview Windows Management Instrumentation (WMI) is a built-in Windows administration framework that allows querying system state, executing commands, and managing configuration both locally and remotely. Attackers abuse WMI to run arbitrary payloads, perform reconnaissance, delete … Read more

Detection Playbook: Windows Command Shell (T1059.003)

T1059.003 · 2026-06-14 Windows Command Shell Execution Windows MITRE ATT&CK → Technique Windows Command Shell (T1059.003) Tactic Execution Platforms Windows Overview Windows Command Shell (T1059.003) refers to adversary abuse of cmd.exe — the native Windows command interpreter — to execute commands, run batch scripts (.bat/.cmd files), and interact with nearly every layer of the operating … Read more

Detection Playbook: PowerShell (T1059.001)

T1059.001 · 2026-06-13 PowerShell Execution Windows MITRE ATT&CK → Technique PowerShell (T1059.001) Tactic Execution Platforms Windows Overview PowerShell (T1059.001) refers to adversary abuse of Windows PowerShell — Microsoft’s built-in scripting language and interactive shell — to execute commands, run scripts, download payloads, and perform post-exploitation activity. Because PowerShell is deeply integrated into Windows administration and … Read more