LoFP LoFP / t1037

t1037

TitleTags
administrator or network operator can create file in this folders for automation purposes. please update the filter macros to remove false positives.
investigate the contents of the \"userinitmprlogonscript\" value to determine of the added script is legitimate
legitimate addition of logon scripts via the command line by administrators or third party tools
legitimate administration activities
legitimate logon scripts or custom shells may trigger false positives. apply additional filters accordingly.