LoFP LoFP / t1003.003

t1003.003

TitleTags
copying sensitive files for legitimate use (eg. backup) or forensic investigation by legitimate incident responder or forensic investigator.
highly possible server administrators will troubleshoot with ntdsutil.exe, generating false positives.
legitimate admin activity
legitimate admin usage
legitimate administrator usage of vssadmin or wmic will create false positives.
legitimate administrator usage of wmic to create a shadow copy.
legitimate administrator using tool for password recovery
legitimate administrator working with shadow copies, access for backup purposes
legitimate backup operation by authorized administrators. matches must be investigated and allowed on a case by case basis.
legitimate backup operation/creating shadow copies
legitimate powershell scripts
legitimate usage to restore snapshots
ntds maintenance
to be determined
transferring sensitive files for legitimate administration work by legitimate administrator