LoFP LoFP / t1134.001

t1134.001

TitleTags
anti-virus
commandlines containing components like cmd accidentally
it is possible legitimate applications will request access to list of know abused windows uac binaries process, filter as needed.
it is possible legitimate applications will request access to winlogon, filter as needed.
jobs and services started with cmd
unknown
unlikely