LoFP LoFP / t1037.001

t1037.001

TitleTags
investigate the contents of the \"userinitmprlogonscript\" value to determine of the added script is legitimate
legitimate addition of logon scripts via the command line by administrators or third party tools
legitimate logon scripts or custom shells may trigger false positives. apply additional filters accordingly.