LoFP LoFP / t1001

t1001

TitleTags
companies, who may use these default ldap-attributes for personal information
other legimate tools, which do adsi (ldap) operations, e.g. any remoting activity by mmc, powershell, windows etc.
some legitimate virtual machine setups or automated testing environments may run qemu with the -nographic flag. review and whitelist approved systems to reduce false alerts.
some security tools or legitimate debugging processes may decode config files similar to powgoop. review and whitelist trusted applications to reduce false alerts.