This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potentially Suspicious Inline JavaScript Execution via NodeJS Binary
Original Source:
[Sigma source]
Title:
Potentially Suspicious Inline JavaScript Execution via NodeJS Binary
Status:
experimental
Description:
Detects potentially suspicious inline JavaScript execution using Node.js with specific keywords in the command line.
References:
-https://www.microsoft.com/en-us/security/blog/2025/04/15/threat-actors-misuse-node-js-to-deliver-malware-and-other-malicious-payloads/
Author:
Microsoft (idea), Swachchhanda Shrawan Poudel (Nextron Systems)
Date:
2025-04-21
modified:
None
Tags:
-'attack.execution'
-'attack.t1059.007'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\node.exe'
OriginalFileName
:
'node.exe'
Product
:
'Node.js'
selection_cmd:
CommandLine|contains|all
:
-'http'
-'execSync'
-'spawn'
-'fs'
-'path'
-'zlib'
condition
:
all of selection_*
Falsepositives:
-Legitimate scripts using Node.js with these modules
Level:
medium