LoFP LoFP / t1202

t1202

TitleTags
in development environment where vscode is used heavily. false positives may occur when developers use task to compile or execute different types of code. remove or add processes accordingly
legitimate administrative scripts
legitimate administrative tasks using `conhost.exe` to spawn child processes such as `cmd.exe`, `powershell.exe`, or `regsvr32.exe`.
legitimate installation or usage of kali linux wsl by administrators or security teams
legitimate usage of \".diagcab\" files
legitimate usage of \"troubleshootingpack\" cmdlet for troubleshooting purposes
legitimate use of sftp with proxy commands for administration or networking tasks
possible but rare
software companies that bundle paexec with their software and rename it, so that it is less embarrassing
system backup or administrator tools
unknown
unlikely
very likely, including launching cmd.exe via run as administrator
weird admins that rename their tools
when executed with the \"-s\" flag. paexec will copy itself to the \"c:\windows\\" directory with a different name. usually like this \"paexec-[xxxxx]-[computername]\"