LoFP LoFP / t1587.001

t1587.001

TitleTags
admins that use psexec or paexec to escalate to the system account for maintenance purposes (rare)
false positive might stem from rare extensions used by other office utilities.
false positives are directly related to their snort rules triggering and the firewall scoring. apply additional filters if the rules are too noisy by disabling them or simply ignoring certain ip ranges that trigger it.
legitimate downloads of \".vhd\" files would also trigger this
software companies that bundle psexec/paexec with their software and rename it, so that it is less embarrassing
unknown
unlikely
users that debug microsoft intune issues using the commands mentioned in the official documentation; see https://learn.microsoft.com/en-us/mem/intune/apps/intune-management-extension
weird admins that rename their tools