LoFP LoFP / t1016

t1016

TitleTags
administrative activity
administrator, hotline ask to user
commonly used by administrators for troubleshooting
if the domains listed in this rule are used as part of an authorized workflow, this rule will be triggered by those events. validate that this is expected activity and tune the rule to fit your environment variables.
legitimate administration activities
legitimate administration activity
legitimate administration use but user and host must be investigated
legitimate powershell scripts that make use of these functions.
legitimate use of the external websites for troubleshooting or network monitoring
powershell and windows command shell are often observed as legit child processes of the jetbrains teamcity service and may require further tuning.
there is a potential for false positives if the dns enumeration tools are used for legitimate purposes, such as debugging or troubleshooting. it is important to investigate any alerts generated by this rule to determine if they are indicative of malicious activity or part of legitimate container activity.
uncommon user command activity can be due to an engineer logging onto a server instance in order to perform manual troubleshooting or reconfiguration.
unlikely