LoFP LoFP / t1202

t1202

TitleTags
automation and orchestration scripts may use this method to execute scripts etc.
in development environment where vscode is used heavily. false positives may occur when developers use task to compile or execute different types of code. remove or add processes accordingly
legitimate usage for administration purposes
legitimate usage of \".diagcab\" files
legitimate usage of \"troubleshootingpack\" cmdlet for troubleshooting purposes
legitimate usage of setres
legitimate use by windows to kill processes opened via wsl (example vscode wsl server)
possible but rare
software companies that bundle paexec with their software and rename it, so that it is less embarrassing
some legacy applications may be run using pcalua.exe. filter these results as needed.
some legacy applications may be run using pcalua.exe. similarly, forfiles.exe may be used in legitimate batch scripts. filter these results as needed.
this search encompasses many commands.
very likely, including launching cmd.exe via run as administrator
weird admins that rename their tools
when executed with the \"-s\" flag. paexec will copy itself to the \"c:\windows\\" directory with a different name. usually like this \"paexec-[xxxxx]-[computername]\"