LoFP LoFP / t1003.006

t1003.006

TitleTags
av signature updates
azure ad connect syncing operations.
files with mimikatz in their filename
genuine dc promotion may trigger this alert.
legitimate administrator using credential dumping tool for password recovery
legitimate powershell scripts
local domain admin account used for azure ad connect
naughty administrators
new domain controllers or certian scripts run by administrators.
unlikely
valid dc sync that is not covered by the filters; please report