LoFP LoFP / admin activity (unclear what they do nowadays with finger.exe)

Techniques

Sample rules

Finger.exe Suspicious Invocation

Description

Detects suspicious aged finger.exe tool execution often used in malware attacks nowadays

Detection logic

condition: selection
selection:
- OriginalFileName: finger.exe
- Image|endswith: \finger.exe