LoFP LoFP / approved installs of windows sdk with debugging tools for windows (windbg).

Techniques

Sample rules

Use of Remote.exe

Description

Remote.exe is part of WinDbg in the Windows SDK and can be used for AWL bypass and running remote files.

Detection logic

condition: selection
selection:
- Image|endswith: \remote.exe
- OriginalFileName: remote.exe