LoFP LoFP / t1059.007

t1059.007

TitleTags
a network operator or systems administrator may utilize an automated host discovery application that may generate false positives. filter as needed.
automation scripting language may used by network operator to do ldap query.
false positives depend on scripts and administrative tools used in the monitored environment
legitimate scripts using node.js with these modules
legitimate software uses the scripts (preinstall, postinstall)
legitimate usage of deno to request a file or bring a dll to a host
legitimate use of node.exe to execute javascript or jsc files on your environment
no false positives have been identified at this time.
some installers might generate a similar behavior. an initial baseline is required
static format arguments - https://petri.com/command-line-wmi-part-3
unknown
unlikely, since this event notifies about blocked application execution. tune your applocker rules to avoid blocking legitimate applications.
wmic.exe fp depend on scripts and administrative methods used in the monitored environment.