LoFP LoFP / t1059.003

t1059.003

TitleTags
high
java tools are known to produce false-positive when loading libraries
legitimate administration script
legitimate use of openedr for remote command execution
legitimate use of screenconnect
legitimate use of screenconnect. disable this rule if screenconnect is heavily used.
unknown
unlikely
unlikely, since this event notifies about blocked application execution. tune your applocker rules to avoid blocking legitimate applications.
valid changes to the startup script