LoFP LoFP / t1018

t1018

TitleTags
a misconfgured network application or firewall may trigger this alert. security scans or test cycles may trigger this alert.
commonly used by administrators for troubleshooting
domain administrators may use this command-line utility for legitimate information gathering purposes.
legitimate admin activity
legitimate administration activities
legitimate administration activity
legitimate script
legitimate use of net.exe utility by legitimate user
legitimate use of netexec by security professionals or system administrators for network assessment and management.
legitimate use of the library for administrative activity
there is a potential for false positives if the dns enumeration tools are used for legitimate purposes, such as debugging or troubleshooting. it is important to investigate any alerts generated by this rule to determine if they are indicative of malicious activity or part of legitimate container activity.
unknown
unlikely