LoFP LoFP / t1218.010

t1218.010

TitleTags
administrator typo might cause some false positives
fqdns that start with a number such as \"7-zip\"
legitimate \".bat\", \".hta\", \".ps1\" or \".vbs\" scripts leverage legitimately often. apply additional filter and exclusions as necessary
some installers might execute \"regsvr32\" with dlls located in %temp% or in %programdata%. apply additional filters if necessary.
some legitimate windows services
unknown
unlikely
unlikely, but can rarely occur. apply additional filters accordingly.