LoFP LoFP / t1561.002

t1561.002

TitleTags
there are som minimal number of normal applications from system32 folder like svchost.exe accessing the mbr. in this case we used 'system32' and 'syswow64' path as a filter for this detection.
will be used sometimes by admins to clean up local flash space