mttaggart / wtfbins

WTF are these binaries doing?! A list of benign applications that mimic malicious behavior.
MIT License
150 stars 12 forks source link

[New WTFBin]: SCS' PowerView.exe triggers PowerSploit's detection #31

Closed Purp1eW0lf closed 1 year ago

Purp1eW0lf commented 1 year ago
image image image
mttaggart commented 1 year ago

Hey @Purp1eW0lf , sorry I'm just getting to this. I am not sure I'd classify this as a WTFBin. Here's why: PowerView.exe is not itself performing anything particularly odd or suspicious. What we have here is a classic false positive on the part of our detection tools. I'll grant it's a weird name, but for me it doesn't quite meet the shape of the WTFBins we've listed.

Purp1eW0lf commented 1 year ago

Absolutely, NP 😎