LoFP LoFP / t1083

t1083

TitleTags
commonly used by administrators for troubleshooting
enumeration of files and directories may not be inherently malicious and noise may come from scripts, automation tools, or normal command line usage. it's important to baseline your environment to determine the amount of expected noise and exclude any known fp's from the rule.
legitimate activities
legitimate powershell scripts
legitimate use by users
the command runshellscript can be used for benign purposes. analyst will have to review the searches and determined maliciousness specially by looking at targeted script.
this search may find additional path traversal exploitation attempts or malformed requests.
this search may find additional path traversal exploitation attempts.
unlikely