Technique T1027
Obfuscated Files or Information
Detection & mitigation
Monitor for suspicious script execution (wscript/cscript) spawning PowerShell with download cradle or encoded commands. Use AMSI and script block logging to detect obfuscated scripts; employ endpoint detection and response (EDR) to identify Agent Tesla behavior such as credential dumping and suspicious network connections.