LoFP LoFP / t1071.004

t1071.004

TitleTags
a third part automation using telegram api.
commands with all of these base64 encoded values are unusual in production environments. filter as needed.
creating a dns entry matching this pattern is very unusual in a production environment. filter as needed.
creating and deleting a dns server object within 30 seconds or less is unusual but not impossible in a production environment. filter as needed.
if you are seeing more results than desired, you may consider reducing the value for threshold in the search. you should also periodically re-run the support search to re-build the ml model on the latest data.
it is possible legitimate traffic can trigger this rule. please investigate as appropriate. the threshold for generating an event can also be customized to better suit your environment.
it's unlikely that a dns entry contains the specific structure used by this attack. filter as needed for your organization.
legitimate use of these services is possible but rare in enterprise environments
researcher, engineering and administrator may create a automation that queries huggingface ai platform hub for accomplishing task.
unknown