XSL Script Processing T1220

Tactic: Stealth

Adversaries may bypass application control and obscure execution of code by embedding scripts inside XSL files. Extensible Stylesheet Language (XSL) files are commonly used to describe the processing and rendering of data within XML files. To support complex operations, the XSL standard includes support for embedded scripting in various languages.

Events covered

4 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 20 rules share fields, values, and exclusions.

Fields filtered most (28 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
process_name12eq 10, regex_match 2wmic.exe, cscript.exe, (?i)msxsl, cmstp.exe, msxsl.exe
CommandLine10contains 7, wildcard 3, regex_match 2, in 1, length_compare 1/format:, (?i)\S+\.x[ms]l\s+.*\.xsl, ://, \\\\, -e
OriginalFileName9eq 9wmic.exe, bcdedit.exe, cmd.exe, installutil.exe, msbuild.exe
EventType8eq 7, starts_with 1start, Image loaded, creation
Image7ends_with 5, starts_with 1, wildcard 1\wmic.exe, \msxsl.exe, ?:\programdata\, ?:\users\, ?:\users\*\appdata\*.exe
dll.name4eq 4jscript.dll, vbscript.dll, jscript9.dll, msxml3.dll, scrobj.dll
host.os.type4eq 4
Hashes3contains 2, is_not_null 1imphash=16a48c3cabf98a9dc1bf02c07fe1ea00, imphash=1b1a3f43bf37b5bfe60751f2ee2f326e, imphash=37777a96245a3c74eb217308f3546f4c
event.type3eq 3start
parent_process_name3eq 3cmd.exe, excel.exe, mspub.exe, powerpnt.exe, svchost.exe
process.args3wildcard 2, eq 1*,#*, *-format*:*, -n, /format*:*, ?:\ProgramData\*
EventID2eq 21, 4688
Type2eq 2
file.name2eq 2cmstp.exe.log, cscript.exe.log, jscript.dll, mshta.exe.log, vbscript.dll
ImageLoaded1ends_with 1\jscript.dll, \vbscript.dll

Top indicator values (151 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
OriginalFileNameeq
wmic.exe
780
EventTypeeq
start
6391
process_nameeq
wmic.exe
666
process_nameeq
msxsl.exe
523
process_nameeq
cscript.exe
367
process_nameeq
mshta.exe
384
process_nameeq
wscript.exe
383
process_nameeq
cmstp.exe
225
CommandLinecontains
/format:
33
CommandLinecontains
://
23
CommandLinecontains
\\\\
26
CommandLinecontains
-e
117
CommandLinecontains
-enc
12
CommandLinecontains
-format:
1
CommandLinecontains
.xsl
1
CommandLinecontains
bootstatuspolicy
110
CommandLinecontains
catalog
112
CommandLinecontains
delete
131
Imageends_with
\wmic.exe
362
Imageends_with
\msxsl.exe
26
dll.nameeq
jscript.dll
34
dll.nameeq
vbscript.dll
34
event.typeeq
start
31078
CommandLineregex_match
(?i)\S+\.x[ms]l\s+.*\.xsl
22
Hashescontains
imphash=16a48c3cabf98a9dc1bf02c07fe1ea00
22
Hashescontains
imphash=1b1a3f43bf37b5bfe60751f2ee2f326e
22
Hashescontains
imphash=37777a96245a3c74eb217308f3546f4c
22
Hashescontains
imphash=9d87c9d67ce724033c0b40cc4ca1b206
22
Hashescontains
imphash=b12619881d79c3acadf45e752a58554a
22
process_nameregex_match
(?i)msxsl
22

Exclusions (197 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process_nameeq
mshta.exe
2
process_nameeq
powershell.exe
2
process_nameeq
regsvr32.exe
2
process_nameeq
wscript.exe
2
user.ideq
S-1-5-18
2
CommandLinecontains
://
1
CommandLinecontains
\\\\
1
CommandLinecontains
\programdata\servicenow\agent-client-collector\config\acc.yml
1
CommandLinecontains
format:csv
1
CommandLinecontains
format:hform
1
CommandLinecontains
format:htable
1
CommandLinecontains
format:list
1
CommandLinecontains
format:mof
1
CommandLinecontains
format:rawxml
1
CommandLinecontains
format:table
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 5 rules

Elastic 10 rules

Splunk 5 rules