LoFP LoFP / some fp could occur with similar tools that uses the same command line '--set-password'

Techniques

Sample rules

Remote Access Tool - AnyDesk Piped Password Via CLI

Description

Detects piping the password to an anydesk instance via CMD and the ‘–set-password’ flag.

Detection logic

condition: selection
selection:
  CommandLine|contains|all:
  - '/c '
  - 'echo '
  - .exe --set-password