LoFP LoFP / t1059.005

t1059.005

TitleTags
administrative activity
false positives should be minimal as the presence of a network connection during such executions increases the likelihood of malicious behavior.
legitimate administrative scripts
microsoft sccm
need tuning applocker or add exceptions in siem
noise and false positive can be seen if the following instant messaging is allowed to use within corporate network. in this case, a filter is needed.
some installers might generate a similar behavior. an initial baseline is required
some software installers or automation scripts may extract and run scripts from archive files in temporary directories. however, it is uncommon for such scripts to initiate outbound network connections immediately upon extraction. this behavior should be considered suspicious and investigated, especially in environments where such scripting is not typical.