LoFP LoFP / legitimate mwc use (unlikely in modern enterprise environments)

Techniques

Sample rules

Microsoft Workflow Compiler Execution

Description

Detects invocation of Microsoft Workflow Compiler, which may permit the execution of arbitrary unsigned code.

Detection logic

condition: selection
selection:
- Image|endswith: \Microsoft.Workflow.Compiler.exe
- OriginalFileName: Microsoft.Workflow.Compiler.exe