LoFP LoFP / t1564.003

t1564.003

TitleTags
administrators may enable or disable this feature for framework testing that may cause some false positive.
false positives are not expected with this detection, unless within the organization there is a legitimate need for headless browsing accessing mockbin.org or mocky.io.
false positives may be present if the application is legitimately used, filter by user or endpoint as needed.
legitimate administrative scripts running from temporary folders.
niche software updaters utilizing hidden batch files in programdata.
unknown