LoFP LoFP / t1074

t1074

TitleTags
administrators may transfer file ownership during employee leave or absence to ensure continued operations by a new or existing employee.
generally used to copy configs or ios images
if known behavior is causing false positives, it can be exempted from the rule.
legitimate exchange system administration activity.
no false positives have been identified at this time.
restoring an rds db instance may be performed legitimately during troubleshooting, development refresh processes, migrations, or disaster-recovery drills. validate the user identity, source ip, automation context, and whether the restoration aligns with a known maintenance or testing workflow before treating the event as suspicious. expected behavior can be exempted through rule exceptions.
traffic mirroring may be done by a system or network administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment. traffic mirroring from unfamiliar users or hosts should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
unknown
updates to approved and trusted ssh executables can trigger this rule.