LoFP LoFP / t1203

t1203

TitleTags
all kind of software downloads
all kinds of software downloads
installer scripts or automated provisioning tools
it is highly recommended to baseline your activity and tune out common business use cases.
legitimate browser install, update and recovery scripts
legitimate use of scx runasprovider executescript.
legitimate use of scx runasprovider invoke_executeshellcommand.
office documents commonly have templates that refer to external addresses, like \"sharepoint.ourcompany.com\" may have to be tuned.
system update scripts using temporary files
unknown
unlikely
users running scripts in the course of technical support operations of software upgrades could trigger this alert. a newly installed program or one that runs rarely as part of a monthly or quarterly workflow could trigger this alert.
you may have to tune certain domains out that excel may call out to, such as microsoft or other business use case domains.