LoFP LoFP / t1016

t1016

TitleTags
administrative activity
administrator or network operator can execute this command. please update the filter macros to remove false positives.
administrator, hotline ask to user
commonly used by administrators for troubleshooting
false positives will be present based on many factors. tune the correlation as needed to reduce too many triggers.
if the domains listed in this rule are used as part of an authorized workflow, this rule will be triggered by those events. validate that this is expected activity and tune the rule to fit your environment variables.
it is uncommon for normal users to execute a series of commands used for network discovery. system administrators often use scripts to execute these commands. these can generate false positives.
legitimate administration activities
legitimate administration activity
legitimate administration use but user and host must be investigated
legitimate use of the external websites for troubleshooting or network monitoring
uncommon user command activity can be due to an engineer logging onto a server instance in order to perform manual troubleshooting or reconfiguration.
unlikely