LoFP LoFP / t1021.003

t1021.003

TitleTags
administrators may leverage dcom to start a process on remote systems, but this activity is usually limited to a small set of hosts or users.
although uncommon, administrators may leverage impackets tools to start a process on remote systems for system administration or automation use cases.
legitimate applications may spawn powershell as a child process of the the identified processes. filter as needed.
legitimate applications may trigger this behavior, filter as needed.
microsoft project has been discontinued since january 2010, so its presence is unlikely in modern environments. if a related child process is observed, verify its legitimacy to rule out potential misuse.
some administrative tasks on remote host
this process should normally never be loading dlls from outside the windows system directory.
this process should normally never be spawning these child processes.
unknown
unlikely