LoFP LoFP / t1071.001

t1071.001

TitleTags
administrative activity
administrative scripts that download files from the internet
administrative scripts that retrieve certain website contents
analyst testing
in modern windows systems, unable to see legitimate usage of this process, however, if an organization has legitimate purpose for this there can be false positives.
it is possible that list of dynamic dns providers is outdated and/or that the url being requested is legitimate.
legitimate installation of code-tunnel as a service
legitimate software uses the scripts (preinstall, postinstall)
legitimate use of cloudflare tunnels will also trigger this.
legitimate use of devtunnels will also trigger this.
legitimate use of telegram bots in the company
legitimate use of visual studio code tunnel
legitimate use of visual studio code tunnel and running code from there
legitimate use of visual studio code tunnel will also trigger this.
legitimate webdav administration
old browsers
rare programs that use bitsadmin and update from regional tlds e.g. .uk or .ca
scripts created by developers and admins
unlikely
user activity (e.g. developer that shared and copied code snippets and used the raw link instead of just copy & paste)
valid requests with this exact user agent to server scripts of the defined names