LoFP LoFP / t1049

t1049

TitleTags
administrators or power users may use this command for troubleshooting.
administrators or power users may use this powershell commandlet for troubleshooting.
commonly used by administrators for troubleshooting
false positives will be present based on many factors. tune the correlation as needed to reduce too many triggers.
legitimate activities
network administrator can use this tool for auditing process.
there is a potential for false positives if the dns enumeration tools are used for legitimate purposes, such as debugging or troubleshooting. it is important to investigate any alerts generated by this rule to determine if they are indicative of malicious activity or part of legitimate container activity.
uncommon user command activity can be due to an engineer logging onto a server instance in order to perform manual troubleshooting or reconfiguration.
unknown