LoFP LoFP / legitimate use by developers as part of nodejs development with visual studio tools

Techniques

Sample rules

Visual Studio NodejsTools PressAnyKey Arbitrary Binary Execution

Description

Detects child processes of Microsoft.NodejsTools.PressAnyKey.exe that can be used to execute any other binary

Detection logic

condition: selection
selection:
  ParentImage|endswith: \Microsoft.NodejsTools.PressAnyKey.exe