LoFP LoFP / t1546.003

t1546.003

TitleTags
although unlikely, administrators may use event subscriptions for legitimate purposes.
dell computers on some versions register an event consumer that is known to cause false positives when brightness is changed by the corresponding keyboard button
dell power manager (c:\program files\dell\powermanager\dpmpowerplansetup.exe)
exclude legitimate (vetted) use of wmi event subscription in your network
false positives may be present from automation based applications (sccm), filtering may be required. in addition, break the query out based on volume of usage. filter process names or f
it is possible some applications will create a consumer and may be required to be filtered. for tuning, add any additional lolbin's for further depth of coverage.
legitimate event consumers
legitimate software creating script event consumers
sccm
unknown (data set is too small; further testing needed)