LoFP LoFP / t1548.002

t1548.002

TitleTags
actions of a legitimate telnet client
anti virus products
as the script block is a blob of text. false positive may occur with scripts that contain the keyword as a reference or simply use it for detection.
domain controller user logon
legitimate cmstp use (unlikely in modern enterprise environments)
legitimate powershell web access installations by administrators
legitimate software installations or updates that modify the shell open command registry keys to these locations.
legitimate use of cmstp.exe utility by legitimate user
legitimate use of fodhelper.exe utility by legitimate user
system administrator usage
unknown
unknown how many legitimate software products use that method
unknown sub processes of wsreset.exe
unlikely
windowsapps located in \"c:\program files\windowsapps\\"