LoFP LoFP / t1027.004

t1027.004

TitleTags
a network operator or systems administrator may utilize an automated powershell script taht execute .net code that may generate false positive. filter is needed.
ansible
legitimate microsoft software - https://twitter.com/gabriele_pippi/status/1206907900268072962
legitimate software from program files - https://twitter.com/gn3mes1s/status/1206874118282448897
legitimate use of dnx.exe by legitimate user
utilization of this tool should not be seen in enterprise environment