LoFP LoFP / t1036.005

t1036.005

TitleTags
administrators may allow execution of specific binaries in non-standard paths. filter as needed.
some administrator activity can be potentially triggered, please add those users to the filter macro.
some legitimate system maintenance tools might use msc files with unusual parameters. filter for specific known maintenance activities in your environment.
some security products seem to spawn these
system components such as daemon-set-controller and kube-scheduler also create pods in the kube-system namespace
system processes copied outside their default folders for testing purposes
third party software might bundle specific versions of system dlls.
third party software naming their software with the same names as the processes mentioned here
unknown flash download locations
unlikely
vendors will often copy system exectables to a different path for application usage.