LoFP LoFP / t1059.005

t1059.005

TitleTags
administrative activity
administrative scripts
legitimate administrative scripts
microsoft sccm
need tuning applocker or add exceptions in siem
noise and false positive can be seen if the following instant messaging is allowed to use within corporate network. in this case, a filter is needed.
some installers might generate a similar behavior. an initial baseline is required