LoFP LoFP / t1059.007

t1059.007

TitleTags
automation scripting language may used by network operator to do ldap query.
false positives depend on scripts and administrative tools used in the monitored environment
legitimate software uses the scripts (preinstall, postinstall)
legitimate usage of deno to request a file or bring a dll to a host
need tuning applocker or add exceptions in siem
some installers might generate a similar behavior. an initial baseline is required