LoFP LoFP / legitimate usage of the script. always investigate what's being registered to confirm if it's benign

Techniques

Sample rules

REGISTER_APP.VBS Proxy Execution

Description

Detects the use of a Microsoft signed script ‘REGISTER_APP.VBS’ to register a VSS/VDS Provider as a COM+ application.

Detection logic

condition: selection
selection:
  CommandLine|contains|all:
  - \register_app.vbs
  - -register