LoFP LoFP / t1547.001

t1547.001

TitleTags
administrators may allow creation of script or exe in this path.
depending on your environment accepted applications may leverage this at times. it is recommended to search for anomalies inidicative of malware.
discord
false positives may be present and will need to be filtered.
fp could be caused by legitimate application writing shortcuts for example. this folder should always be inspected to make sure that all the files in there are legitimate
legitimate admin or third party scripts. baseline according to your environment
legitimate administrative use
legitimate administrator sets up autorun keys for legitimate reason
legitimate administrator sets up autorun keys for legitimate reasons.
legitimate software automatically (mostly, during installation) sets up autorun keys for legitimate reasons.
rare legitimate usage of some of the extensions mentioned in the rule
software installers downloaded and used by users
software using weird folders for updates
there are many legitimate applications that must execute on system startup and will use these registry keys to accomplish that task.
updated windows application needed in safe boot may used this registry