LoFP LoFP / t1059.005

t1059.005

TitleTags
administrative activity
because this file are always created by outlook in normal operations, you should investigate all results.
false positives should be minimal as the presence of a network connection during such executions increases the likelihood of malicious behavior.
legitimate administrative scripts
legitimate mmc operations or extensions loading these libraries
microsoft sccm
need tuning applocker or add exceptions in siem
noise and false positive can be seen if the following instant messaging is allowed to use within corporate network. in this case, a filter is needed.
some installers might generate a similar behavior. an initial baseline is required
some software installers or automation scripts may extract and run scripts from archive files in temporary directories. however, it is uncommon for such scripts to initiate outbound network connections immediately upon extraction. this behavior should be considered suspicious and investigated, especially in environments where such scripting is not typical.
unknown