LoFP LoFP / t1040

t1040

TitleTags
admins may setup new or modify old spans, or use a monitor for troubleshooting
full network packet capture may be done by a system or network administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment. full network packet capture from unfamiliar users or hosts should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
legitimate administration activities
legitimate administration activity
legitimate administration activity to troubleshoot network issues
legitimate administrator or user uses network sniffing tool for legitimate reasons.
legitimate network diagnostic scripts.
legitimate use
some normal use of this command may originate from server or network administrators engaged in network troubleshooting.