F004LOW
OUTLOOK.EXE RWX injected region
vol_cmdlinevol_handlesvol_malfindvol_netscan+2
Benign / FP50 proofs
F010MEDIUM
UpdaterUI.exe RWX injected region
vol_cmdlinevol_handlesvol_malfindvol_psscan+1
Benign / FP50 proofs
F011LOW
subject_srv.exe remote-management listener (C2/Remote access)
get_amcachevol_cmdlinevol_netscanvol_pstree
Benign / FP139 proofs
F024LOW
Remote access service subject_srv.exe listening with external connection
vol_netscanvol_psscanvol_pstree
Benign / FP50 proofs
F033LOW
Local high-port listeners and loopback staging context
extract_network_iocsvol_cmdlinevol_handlesvol_netscan+1
Benign / FP50 proofs