Visual Basic (T1059.005)

View on ATT&CK

In Playbook

Associated Tactics

  • Execution

Execution (TA0002)

The adversary is trying to run malicious code. Execution consists of techniques that result in adversary-controlled code running on a local or remote system. Techniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data. For example, an adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery.

View on ATT&CK

Procedure Examples

Description Source(s)
.NET Team. (2020, March 11). Visual Basic support planned for .NET 5.0. Retrieved June 23, 2020. VB .NET Mar 2020
Kellie Eickmeyer. (2022, February 7). Helping users stay safe: Blocking internet macros by default in Office. Retrieved February 7, 2022. Default VBS macros Blocking
Microsoft. (2011, April 19). What Is VBScript?. Retrieved March 28, 2020. Microsoft VBScript
Microsoft. (2019, June 11). Office VBA Reference. Retrieved June 23, 2020. Microsoft VBA
Microsoft. (n.d.). Visual Basic documentation. Retrieved June 23, 2020. VB Microsoft
Wikipedia. (n.d.). Visual Basic for Applications. Retrieved August 13, 2020. Wikipedia VBA