LoFP LoFP / t1003.003

t1003.003

TitleTags
copying sensitive files for legitimate use (eg. backup) or forensic investigation by legitimate incident responder or forensic invetigator
highly possible server administrators will troubleshoot with ntdsutil.exe, generating false positives.
legitimate admin activity
legitimate admin usage
legitimate administrator usage of vssadmin or wmic will create false positives.
legitimate administrator using tool for password recovery
legitimate administrator working with shadow copies, access for backup purposes
legitimate backup operation/creating shadow copies
legitimate powershell scripts
legitimate usage to restore snapshots
legtimate administrator usage of wmic to create a shadow copy.
ntds maintenance
to be determined
transferring sensitive files for legitimate administration work by legitimate administrator