LoFP LoFP / t1020

t1020

TitleTags
allowed administrative activities.
benign changes to a db instance
confirm if the modification or deletion was part of a planned change or maintenance activity.
false positives should be limited as this analytic identifies renamed instances of `rclone.exe`. filter as needed if there is a legitimate business use case.
false positives should be limited as this is restricted to the rclone process name. filter or tune the analytic as needed.
the same functionality can be implemented by admin scripts, correlate with name and creator
this search will return false positives for any legitimate traffic captures by network administrators.
traffic mirroring may be done by a system or network administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment. traffic mirroring from unfamiliar users or hosts should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
verify if the modification or deletion was performed by an authorized administrator.