LoFP LoFP / t1049

t1049

TitleTags
administrators or power users may use this command for troubleshooting.
administrators or power users may use this powershell commandlet for troubleshooting.
commonly used by administrators for troubleshooting
false positives will be present based on many factors. tune the correlation as needed to reduce too many triggers.
legitimate activities
network administrator can use this tool for auditing process.
uncommon user command activity can be due to an engineer logging onto a server instance in order to perform manual troubleshooting or reconfiguration.