LoFP LoFP / t1547.001

t1547.001

TitleTags
administrative activity, still unlikely
automatic registry modifications during legitimate software installations
depending on your environment accepted applications may leverage this at times. it is recommended to search for anomalies inidicative of malware.
discord
fp could be caused by legitimate application writing shortcuts for example. this folder should always be inspected to make sure that all the files in there are legitimate
legitimate admin or third party scripts. baseline according to your environment
legitimate administrative activity or software installations
legitimate administrative use
legitimate administrator sets up autorun keys for legitimate reason
legitimate administrator sets up autorun keys for legitimate reasons.
legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reason
legitimate software or add-in installations and administrative configurations
rare legitimate usage of some of the extensions mentioned in the rule
software installers downloaded and used by users
software using weird folders for updates
unknown
usage of reg.exe or powershell to modify user shell folders for legitimate purposes; but rare.