LoFP LoFP / t1204.002

t1204.002

TitleTags
all kind of software downloads
all kinds of software downloads
legitimate administrative actions using mmc to execute misnamed `.msc` files.
legitimate applications packaged with advanced installer using package support framework
legitimate installation of new application.
legitimate installation of unsigned packages for legitimate purposes such as development or testing
legitimate macro usage. add the appropriate filter according to your environment
newly setup system.
rare legitimate usage of some of the extensions mentioned in the rule
some legitimate applications installation which have been missed from filtering can generate fps, thus baselining and tuning is recommended before deploying to production
some tuning might be required to allow or remove certain locations used by the rule if you consider them as safe locations
this rule is to explore new applications on an endpoint. false positives depends on the organization.
unconventional but non-malicious usage of rlo or reversed extensions.
unknown
unknown flash download locations
unlikely in most cases, further investigation should be done in the commandline of the browser process to determine the context of the url accessed.
unlikely, since this event notifies about blocked application execution. tune your applocker rules to avoid blocking legitimate applications.