Query Details

W Script C Script Executing Java Script From User Profile

Query

DeviceProcessEvents
| where InitiatingProcessFileName in ("openwith.exe", "explorer.exe")
| where FileName in ('wscript.exe','cscript.exe')
| where ProcessCommandLine contains @"c:\Users\" and ProcessCommandLine contains ".js"

About this query

Explanation

This query is designed to detect potentially malicious activity involving the execution of JavaScript files on a Windows system. Specifically, it looks for instances where the processes wscript.exe or cscript.exe are launched by either openwith.exe or explorer.exe. These processes are used to run scripts, and if they are executing JavaScript files (.js) located within a user's profile directory (e.g., C:\Users\), it could indicate an attempt to run harmful scripts. This behavior is often associated with user actions, such as opening a malicious file, which could lead to executing unwanted or harmful code. The query is part of a security measure to identify and mitigate risks associated with executing malicious JavaScript code.