LoFP LoFP / t1202

t1202

TitleTags
in development environment where vscode is used heavily. false positives may occur when developers use task to compile or execute different types of code. remove or add processes accordingly
legitimate usage of \".diagcab\" files
legitimate usage of \"troubleshootingpack\" cmdlet for troubleshooting purposes
possible but rare
software companies that bundle paexec with their software and rename it, so that it is less embarrassing
some legacy applications may be run using pcalua.exe. filter these results as needed.
some legacy applications may be run using pcalua.exe. similarly, forfiles.exe may be used in legitimate batch scripts. filter these results as needed.
this detection may generate a few false positives, such as legitimate software updates or legitimate system maintenance activities that modify the runmru key. however, the exclusion of mrulist value changes helps reduce the number of false positives by focusing only on actual command entries. add any specific false positives to the built in filter to reduce notables as needed.
unlikely
very likely, including launching cmd.exe via run as administrator
weird admins that rename their tools
when executed with the \"-s\" flag. paexec will copy itself to the \"c:\windows\\" directory with a different name. usually like this \"paexec-[xxxxx]-[computername]\"