Closed Purp1eW0lf closed 1 year ago
Hey @Purp1eW0lf , sorry I'm just getting to this. I am not sure I'd classify this as a WTFBin. Here's why: PowerView.exe
is not itself performing anything particularly odd or suspicious. What we have here is a classic false positive on the part of our detection tools. I'll grant it's a weird name, but for me it doesn't quite meet the shape of the WTFBins we've listed.
Absolutely, NP 😎
C:\SCS\Powerview\Powerview.exe
orC:\Program Files (x86)\SCS\PowerView\PowerView.exe