For now, I’ve decided to exception this specific command chain, since I can’t find clear evidence of malicious activity.
It would be great if Rapid7 could shed some light on this, whether it’s a false positive, a recent change in the detection logic, or expected Office/AppVLP behavior.
Yes. We have a few hundred of these alerts today. They seem to be related to the recent Microsoft Office update from June 25. Seems that as computers install this update we get one of these alerts.
Hi folks, our Threat Intelligence team have reviewed these alerts add added a rule suppression to reduce the noise from this, thanks for raising it @anwe