LoFP LoFP / t1070

t1070

TitleTags
admin activity
admin changing date of files.
administrator or administrator scripts might delete packages for several reasons (debugging, troubleshooting).
administrators or power users may remove their shares via cmd line
bucket components may be deleted by a system or network administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment. bucket component deletions by unfamiliar users or hosts should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
bucket components may be deleted or adjusted by a system or network administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment. bucket component deletions by unfamiliar users or hosts should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
changes made to or by the local ntp service
during log rotation
during uninstallation of the iis service
during uninstallation of the tomcat server
false positives levels will differ depending on the environment. you can use a combination of parentimage and other keywords from the commandline field to filter legitimate activity
files that are interacted with that have these extensions legitimately
hyperv or other virtualization technologies with binary not listed in filter portion of detection
installer tools that disable services, e.g. before log collection agent installation
landesk ldclient ivanti-psmodule (ps encodedcommand)
legitimate admin script
legitimate administration activities
legitimate administrator deletes shadow copies using operating systems utilities for legitimate reason
legitimate administrators may run these commands
legitimate deactivation by administrative staff
legitimate powershell scripts
legitimate script that disables the command history
legitimate usage of sdelete
legitime usage of sdelete
log rotation.
maintenance activity
other third party applications not listed.
possible fp during log rotation
rare need to clear logs before doing something. sometimes used by installers or cleaner scripts. the script should be investigated to determine if it's legitimate
rollout of log collection agents (the setup routine often includes a reset of the local eventlog)
scripts and administrative tools used in the monitored environment
system provisioning (system reset before the golden image creation)
unlikely
user and network administrator can execute this command.
will be used sometimes by admins to clean up local flash space