LoFP LoFP / t1564.004

t1564.004

TitleTags
administrative or software activity
applications could use this notation occasionally which might generate some false positives. in that case investigate the parent and child process.
false positives may be generated by process executions within the commandline, regex has been provided to minimize the possibilty.
software installers
some false positives might occur with binaries download via github
this rule isn't looking for any particular binary characteristics. as legitimate installers and programs were seen embedding hidden binaries in their ads. some false positives are expected from browser processes and similar.
unlikely
very possible