LoFP LoFP / t1059.004

t1059.004

TitleTags
admin activity
administrators or installed processes that leverage nohup
false positives may be present based on legitimate software being utilized. filter as needed.
installer scripts or automated provisioning tools
legitimate administrative activity modifying sysrq for debugging or recovery. please update the filter macros to remove false positives.
legitimate files with similar naming patterns (very unlikely).
legitimate software that uses these patterns
legitimate usage of the unsafe option
rare false positives might show up from child processes such as sh. apply additional filters as needed.
system update scripts using temporary files
unknown
unless an administrator is using these commands to troubleshoot or audit a system, the execution of these commands should be monitored.
valid changes to the startup script