What is a script-based attack?¶
A script-based attack uses instructions interpreted by an existing program - such as PowerShell, a command shell, JavaScript or Python - to carry out malicious activity. The interpreter is usually a legitimate tool; the evidential issue is the instruction it received and the outcome it produced.
Scripts appeal to offenders because they can automate many actions, use trusted system components and be changed quickly. They may arrive as a file, be embedded in a document, be pasted into a console, be supplied in a command line or be downloaded directly into memory.
Reconstruct the instruction chain¶
Start with the interpreter process and work both backwards and forwards. Its parent may show whether it was launched by a document, browser, remote-access session, scheduled task or interactive user. Its command line, script logs or console history may preserve all or part of the instruction.
Then identify the consequences:
- child processes and commands;
- files read, written or deleted;
- accounts, services or scheduled tasks changed;
- external addresses contacted and content retrieved;
- credentials or data accessed; and
- security controls queried or altered.
The original script may no longer exist as a standalone file. Process telemetry, script-block logging, memory, network records and resulting artefacts can nevertheless preserve enough of the sequence to explain what happened.
Obfuscation is a clue, not a conclusion¶
Encoding, fragmented strings and dynamically constructed commands can frustrate inspection and may support an inference of concealment. Investigators should retain the original representation as evidence and document how any decoded or de-obfuscated version was produced.
Analysis of a script shows what it was capable of doing under specified conditions. Proof of execution requires records from the affected environment. Attribution requires another step again: accounts and devices can be shared or compromised, and an automated process may have invoked the interpreter.
Key takeaway
Explain a script-based attack as a chain from launcher to instruction to observable effect, while keeping code capability, actual execution and personal attribution distinct.