LoFP LoFP / t1106

t1106

TitleTags
as the script block is a blob of text. false positive may occur with scripts that contain the keyword as a reference or simply use it for detection.
false-positives (fp) can appear if the pid file is legitimate and holding a process id as intended. to differentiate, if the pid file is an executable or larger than 10 bytes, it should be ruled suspicious.
legitimate powershell scripts that make use of psreflect to access the win32 api
legitimate powershell scripts that make use of these functions.
legitimate use of debugging tools
unlikely