LoFP LoFP / t1049

t1049

TitleTags
commonly used by administrators for troubleshooting
legitimate activities
powershell and windows command shell are often observed as legit child processes of the jetbrains teamcity service and may require further tuning.
there is a potential for false positives if the dns enumeration tools are used for legitimate purposes, such as debugging or troubleshooting. it is important to investigate any alerts generated by this rule to determine if they are indicative of malicious activity or part of legitimate container activity.
uncommon user command activity can be due to an engineer logging onto a server instance in order to perform manual troubleshooting or reconfiguration.
unknown