LoFP LoFP / t1059.007

t1059.007

TitleTags
expected during applocker policy testing and audit mode deployments
false positives depend on scripts and administrative tools used in the monitored environment
high false positive rate expected in environments where ai agent tooling is authorized and commonly used.
legitimate pre-commit hooks or ci/cd pipeline jobs that use a script to run a credential scanner as part of a security check.
legitimate scripts using node.js with these modules
legitimate software uses the scripts (preinstall, postinstall)
legitimate usage of deno to request a file or bring a dll to a host
legitimate use of node.exe to execute javascript or jsc files on your environment
some installers might generate a similar behavior. an initial baseline is required
static format arguments - https://petri.com/command-line-wmi-part-3
this rule will be triggered when a new agent skill is installed regardless if it is benign or malicious.
unknown
unlikely, since this event notifies about blocked application execution. tune your applocker rules to avoid blocking legitimate applications.
wmic.exe fp depend on scripts and administrative methods used in the monitored environment.