WScript execution of heavily obfuscated JS with junk comments (LausivLoader)
Detects the execution of JavaScript files using wscript.exe from user-writable directories (e.g., Temp, Downloads, AppData) that exhibit high levels of obfuscation. The rule specifically flags scripts containing a high ratio of comment lines to code, a technique often used in the LausivLoader malware family to mask malicious payloads constructed using String.fromCharCode.
Splunk (SPL)

