LoFP LoFP / t1021.004

t1021.004

TitleTags
administrative activity using a remote port forwarding to a local port
false positives may be present if the organization allows for ssh tunneling outbound or internally. filter as needed.
legitimate administrator activity
legitimate user activity.
legitimate user wrong password attempts.
this is not a common command to be executed. filter as needed.