LoFP LoFP / t1021.003

t1021.003

TitleTags
administrators may leverage dcom to start a process on remote systems, but this activity is usually limited to a small set of hosts or users.
although uncommon, administrators may leverage impackets tools to start a process on remote systems for system administration or automation use cases.
legitimate applications may spawn powershell as a child process of the the identified processes. filter as needed.
legitimate applications may trigger this behavior, filter as needed.
some administrative tasks on remote host
unlikely