LoFP LoFP / t1027

t1027

TitleTags
administrative activity
administrative script libraries
amazon ssm document worker
ansible
as this is a general purpose rule, legitimate usage of the encode functionality will trigger some false positives. apply additional filters accordingly
automated tools such as jenkins may encode or decode files as part of their normal behavior. these events can be filtered by the process executable or username values.
certain kinds of security testing may trigger this alert. powershell scripts that use high levels of obfuscation or have unusual script block payloads may trigger this alert.
disk device errors
files that are interacted with that have these extensions legitimately
known false positive caused with python anaconda
legitimate activities
legitimate files with similar naming patterns (very unlikely).
legitimate large or encoded powershell scripts (automation frameworks, installers, or admin tooling) can exhibit high entropy or uneven character distributions.
legitimate microsoft software - https://twitter.com/gabriele_pippi/status/1206907900268072962
legitimate powershell scripts that reconstruct to a confirmed benign installer, updater, or administrative workflow for the same user and host scope.
legitimate powershell scripts which makes use of encryption.
legitimate py2exe binaries
legitimate script work
legitimate software from program files - https://twitter.com/gn3mes1s/status/1206874118282448897
legitimate usage of sdelete
legitimate use of dnx.exe by legitimate user
legitimate use of python for decoding data, which is uncommon in typical enterprise environments but possible in development or data analysis contexts.
legitimate use of the tool by administrators or users to update metadata of a binary
legitimate use to pass password to different powershell commands
legitimate used of encrypted zip files
monitoring activity
scripts and administrative tools used in the monitored environment
there legitimate reasons to export certificates. investigate the activity to determine if it's benign
unknown
unlikely
unlikely, because no sane admin pings ip addresses in a hexadecimal form
utilization of this tool should not be seen in enterprise environment
various legitimate software is bundled from python code into executables
windows defender atp