title: MSHTA spwaned by SVCHOST as seen in LethalHTA status: experimental description: Detects MSHTA.EXE spwaned by SVCHOST described in report references: - https://codewhitesec.blogspot.com/2018/07/lethalhta.html tags: - attack.defense_evasion - attack.execution - attack.t1170 author: Markus Neis date: 2018/06/07 logsource: category: process_creation product: windows detection: selection: ParentImage: '*\svchost.exe' Image: '*\mshta.exe' condition: selection falsepositives: - Unknown level: high