LoFP LoFP / t1557.001

t1557.001

TitleTags
legitimate files with these rare hacktool names
legitimate use of the impacket tools
legitimate windivert driver usage
uncommon but legitimate windows administrator or software tasks that make use of the encrypting file system rpc calls. verify if this is common activity (see description).
unlikely