LoFP LoFP / t1003.002

t1003.002

TitleTags
av signature updates
copying sensitive files for legitimate use (eg. backup) or forensic investigation by legitimate incident responder or forensic investigator.
dumping hives for legitimate purpouse i.e. backup or forensic investigation
files with mimikatz in their filename
legitimate administrator using credential dumping tool for password recovery
legitimate administrator using tool for password recovery
legitimate administrator working with shadow copies, access for backup purposes
legitimate use during memory forensics; if not part of authorized analysis, warrants urgent investigation
legitimate use of volume shadow copy mounts (backups maybe).
legitimate use of vssvc. maybe backup operations. it would usually be done by c:\windows\system32\vssvc.exe.
naughty administrators
powershell scripts fixing hivenightmare / serioussam acls
rare cases of administrative activity
some rare backup scenarios
transferring sensitive files for legitimate administration work by legitimate administrator
unknown
unlikely