Script engine invoked with an SVG file on its command line
AN1407's real shape is a file-write followed within MITRE's TimeWindow by script-engine execution, network callback or credential collection — a three-stage correlation Sigma cannot express in one event. What survives to a single process_creation record is the deviation this rule matches instead: an SVG, an image format with no legitimate reason to be fed to a script host, on the command line of wscript.exe, cscript.exe, mshta.exe or rundll32.exe. The file-extension gate is MITRE's FileExtensionPattern knob restricted to .svg and .svgz; ParentProcessWhitelist has no expression here because the rule gates on the argument rather than on what launched the engine. A hit shows a script host was pointed at an SVG, not that the SVG carried a script tag or that anything fired afterwards — confirming smuggled content requires opening the file, which this event never does — a genuine, unmodified icon and a smuggled payload are indistinguishable at this level. The gate is also purely lexical, so an SVG fetched from an extensionless route or a query-string path (http://host/asset?id=1), or renamed on disk before invocation, leaves nothing for it to match. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0510, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full descriptionShow less
The detection
The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.
detection.yml
title: Script engine invoked with an SVG file on its command lineid: 64ab9e70-032b-4725-aa2c-651b160ec9fbstatus: experimentaldescription: | AN1407's real shape is a file-write followed within MITRE's TimeWindow by script-engine execution, network callback or credential collection — a three-stage correlation Sigma cannot express in one event. What survives to a single process_creation record is the deviation this rule matches instead: an SVG, an image format with no legitimate reason to be fed to a script host, on the command line of wscript.exe, cscript.exe, mshta.exe or rundll32.exe. The file-extension gate is MITRE's FileExtensionPattern knob restricted to .svg and .svgz; ParentProcessWhitelist has no expression here because the rule gates on the argument rather than on what launched the engine. A hit shows a script host was pointed at an SVG, not that the SVG carried a script tag or that anything fired afterwards — confirming smuggled content requires opening the file, which this event never does — a genuine, unmodified icon and a smuggled payload are indistinguishable at this level. The gate is also purely lexical, so an SVG fetched from an extensionless route or a query-string path (http://host/asset?id=1), or renamed on disk before invocation, leaves nothing for it to match. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0510, not hand-written and not tested by its author. Any lab result is on this rule's own page.references: - https://attack.mitre.org/techniques/T1027/017 - https://attack.mitre.org/detectionstrategies/DET0510author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags: - attack.defense-evasion - attack.t1027.017logsource: category: process_creation product: windowsdetection: selection_engine: Image|endswith: - '\wscript.exe' - '\cscript.exe' - '\mshta.exe' - '\rundll32.exe' selection_svg_arg: CommandLine|contains: - '.svg' - '.svgz' condition: selection_engine and selection_svg_argfalsepositives: - "Legitimate SVG open, preview or conversion via a script wrapper — for example a help-desk or documentation tool shelling out to wscript.exe against C:\\tools\\svgviewer\\open.vbs icons.svg to preview a genuine, unmodified icon, or an asset build pipeline invoking rundll32 or wscript against a path or argument that contains '.svg' as a normal batch-conversion step. This is indistinguishable from smuggled content at the process_creation level because the event never inspects file content." - "HTA-based installers and setup wizards that hardcode a path to an .svg logo or icon in their mshta.exe command line for branding, a cosmetic reference with no script content involved." - "Design and publishing automation that shells out to rundll32 or a wscript helper to batch-convert or rasterize .svg assets as a normal step in a release or documentation pipeline."level: mediumSentinel · KQL
Run this as a search.
DeviceProcessEvents| where ((FolderPath endswith "\\wscript.exe" or FolderPath endswith "\\cscript.exe" or FolderPath endswith "\\mshta.exe" or FolderPath endswith "\\rundll32.exe") and (ProcessCommandLine contains ".svg" or ProcessCommandLine contains ".svgz"))
Splunk · SPL
Run this as a search.
index=* ((Image="*\\wscript.exe" OR Image="*\\cscript.exe" OR Image="*\\mshta.exe" OR Image="*\\rundll32.exe") AND (CommandLine="*.svg*" OR CommandLine="*.svgz*"))Elastic · ES|QL
Run this as a search.
FROM logs-*| WHERE ((TO_LOWER(process.executable) LIKE "*\\\\wscript.exe" OR TO_LOWER(process.executable) LIKE "*\\\\cscript.exe" OR TO_LOWER(process.executable) LIKE "*\\\\mshta.exe" OR TO_LOWER(process.executable) LIKE "*\\\\rundll32.exe") AND (TO_LOWER(process.command_line) LIKE "*.svg*" OR TO_LOWER(process.command_line) LIKE "*.svgz*"))
Wazuh · XML rule
Deploy to your manager — this is a rule, not a search.
<group name="sigma,windows,process_creation,"> <!-- Rule ids must be unique on your manager; 100000+ is the user range. --> <rule id="100000" level="7"> <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. --> <field name="Image" type="pcre2">(?i)(\\wscript\.exe$|\\cscript\.exe$|\\mshta\.exe$|\\rundll32\.exe$)</field> <field name="CommandLine" type="pcre2">(?i)(\.svg|\.svgz)</field> <description>Script engine invoked with an SVG file on its command line</description> <mitre> <id>T1027.017</id> </mitre> </rule></group>
Verdicts · reactions · comments
Community
Verdicts from engineers who actually deployed it, and the conversation around it.
Nobody has run this in a real environment and said what happened.
Verdicts from engineers who deployed it
0 castNo verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.
Log in to report a verdict.
Log in to join the discussion.
No comments yet. Someone who deploys this will have something to say about it.