LoFP LoFP / t1055.001

t1055.001

TitleTags
false positives should be limited, however it is possible to filter by processes.process_name and specific processes (ex. wscript.exe). filter as needed. this may need modification based on edr telemetry and how it brings in registry data. for example, removal of (default).
false positives will be limited to applications that require rasautou.exe to load a dll from disk. filter as needed.
unlikely