LoFP LoFP / t1033

t1033

TitleTags
admin activity
administrator may execute this commandline tool for auditing purposes. filter as needed.
administrators or power users may use this command for troubleshooting.
administrators or power users may use this command for troubleshooting. filter as needed.
administrators or power users may use this powershell commandlet for troubleshooting.
commonly used by administrators for troubleshooting
dministrator may execute this commandline tool for auditing purposes. filter as needed.
false positives will be present based on many factors. tune the correlation as needed to reduce too many triggers.
legitimate admin scripts may use the same technique, it's better to exclude specific computers or users who execute these commands or scripts often
legitimate administration activities
legitimate administrator or user enumerates local users for legitimate reason
legitimate powershell scripts
monitoring activity
network administrator can use this command tool to audit rdp access of user in specific network or host.
programs that use the same command line flags
scripts and administrative tools used in the monitored environment
security testing tools and frameworks may run this command. some normal use of this command may originate from automation tools and frameworks.
some normal use of this program, at varying levels of frequency, may originate from scripts, automation tools and frameworks. usage by non-engineers and ordinary users is unusual.
uncommon user command activity can be due to an engineer logging onto a server instance in order to perform manual troubleshooting or reconfiguration.
unlikely