LoFP LoFP / t1129

t1129

TitleTags
legitimate installation of approved powershell modules may trigger this detection. verify module sources to reduce false positives.
legitimate software updates or remote imaging tools may load images from shared folders. filter these detections for approved applications to reduce false positives.
legitimate use of the tabexpansion function is rare but possible. filter alerts if direct calls are from trusted administrative or development activities.
no false positives have been identified at this time.
some legitimate excel add-ins and administrative tools may create xll files outside typical locations. review and allow approved applications to reduce false positives.
vscode extensions or similar legitimate tools might use unsigned .node files. these should be investigated on a case-by-case basis, and whitelisted if determined to be benign.