LoFP LoFP / these programs may be used by windows developers but use by non-engineers is unusual.

Techniques

Sample rules

Trusted Developer Application Usage

Description

Identifies possibly suspicious activity using trusted Windows developer activity.

Detection logic

event.category:process and event.type:(start or process_started) and process.name:(MSBuild.exe or msxsl.exe)