LoFP LoFP / t1566.001

t1566.001

TitleTags
cases in which a user mounts an image file for legitimate reasons
file located in the appdata folder with trusted signature
legitimate macro files downloaded from the internet
legitimate macro files sent as attachments via emails
legitimate usage of hdiutil by administrators and users.
legitimate used of encrypted zip files
opening of headers or footers in email signatures that include svg images or legitimate svg attachments
potential fp by sysadmin opening a zip file containing a legitimate iso file
software installation iso files
this will alert on legitimate macro usage as well, additional tuning is required
unknown
unlikely
very common in environments that rely heavily on macro documents