@Paxxi @GossiTheDog as was mentioned earlier, these tools are TACTICS, not declared as malware. They are commonly used by criminals during compromises, so it is prudent for orgs to track such activity. Of course that means dealing with false positives when your staff include people like those in this thread...