LoFP LoFP / t1204.001

t1204.001

TitleTags
false positives may be high depending on the environment and consistent use of isos mounting. restrict to servers, or filter out based on commonly used iso names. filter as needed.
legitimate applications using runmru with http links
legitimate powershell commands that use hidden windows for automation tasks may trigger this detection. the search specifically looks for patterns typical of fakecaptcha campaigns. you may need to add additional exclusions for legitimate administrative activities in your environment by modifying the filter macro.
unknown
unlikely