LoFP LoFP / t1546.015


false positives may be present and some filtering may be required.
false positives will be present if any scripts are adding to inprocserver32. filter as needed.
legitimate powershell scripts
legitimate use
legitimate use of the dll.
maybe some system utilities in rare cases use linking keys for backward compatibility
network operrator may use this command.
probable legitimate applications. if you find these please add them to an exclusion list
some installed utilities (i.e. onedrive) may serve new com objects at user-level