LoFP LoFP / t1074

t1074

TitleTags
administrators may create drive data transfer requests during employee offboarding to preserve files for a manager or successor account.
customer takeout exports may be created for legal hold, compliance, migration, or user-requested backups. verify the initiator, target user, and export scope are expected.
generally used to copy configs or ios images
if known behavior is causing false positives, it can be exempted from the rule.
legitimate exchange system administration activity.
restoring an rds db instance may be performed legitimately during troubleshooting, development refresh processes, migrations, or disaster-recovery drills. validate the user identity, source ip, automation context, and whether the restoration aligns with a known maintenance or testing workflow before treating the event as suspicious. expected behavior can be exempted through rule exceptions.
traffic mirroring may be done by a system or network administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment. traffic mirroring from unfamiliar users or hosts should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
unknown
updates to approved and trusted ssh executables can trigger this rule.