LoFP LoFP / t1083

t1083

TitleTags
administrator or network operator can use this application for automation purposes. please update the filter macros to remove false positives.
commonly used by administrators for troubleshooting
enumeration of files and directories may not be inherently malicious and noise may come from scripts, automation tools, or normal command line usage. it's important to baseline your environment to determine the amount of expected noise and exclude any known fp's from the rule.
legitimate activities
legitimate powershell scripts
legitimate use by users
unlikely