LoFP LoFP / t1069

t1069

TitleTags
administrator activity
administrator script
administrators may leverage powerview for legitimate purposes, filter as needed.
administrators or power users may use adsisearcher for troubleshooting.
administrators or power users may use this command for troubleshooting.
administrators or power users may use this powershell commandlet for troubleshooting.
administrators or power users may use this powerview for troubleshooting.
administrators or power users may use this powerview functions for troubleshooting.
false positives may be present. tune as needed.
false positives should be limited as the analytic is specific to a filename with extension .zip. filter as needed.
false positives should be limited as the arguments used are specific to sharphound. filter as needed or add more command-line arguments as needed.
false positives should be limited as the command-line arguments are specific to soaphound. filter as needed.
false positives should be limited as the destination port is specific to active directory web services protocol, however we recommend utilizing this analytic to hunt for non-standard processes querying the adws port. filter by app or dest_ip to ad servers and remove known proceses querying adws.
false positives should be limited as this is specific to a file attribute not used by anything else. filter as needed.
false positives will be present based on many factors. tune the correlation as needed to reduce too many triggers.
legitimate admin activity
legitimate administration activities
legitimate powershell scripts that make use of these functions.
other programs that use these command line option and accepts an 'all' parameter
some false positives may arise in some environment and this may require some tuning. add additional filters or reduce level depending on the level of noise
system administrator usage
this detection will require tuning to provide high fidelity detection capabilties. tune based on src addresses (corporate offices, vpn terminations) or by groups of users. not every user with aws access should have permission to delete groups (least privilege).