LoFP LoFP / t1083

t1083

TitleTags
administrator or network operator can use this application for automation purposes. please update the filter macros to remove false positives.
commonly used by administrators for troubleshooting
enumeration of files and directories may not be inherently malicious and noise may come from scripts, automation tools, or normal command line usage. it's important to baseline your environment to determine the amount of expected noise and exclude any known fp's from the rule.
legitimate activities
legitimate powershell scripts
legitimate use by users
legitimate use of opening files from remote hosts by administrators or users. however, storing passwords in text readable format could potentially be a violation of the organization's policy. any match should be investigated further.
legitimate use of trufflehog by security teams or developers.
unknown