LoFP LoFP / t1087

t1087

TitleTags
administrative activity
administrator activity
administrators configuring new users.
administrators may leverage powerview for legitimate purposes, filter as needed.
adws is used by a number of legitimate applications that need to interact with active directory. these applications should be added to the allow-listing to avoid false positives.
another tool that uses the command line switches of psloglist
authorized administrative activity
commonly run by administrators
false positives depend on scripts and administrative tools used in the monitored environment
go utilities that use staaldraad awesome ntlm library
if source account name is not an admin then its super suspicious
inventory tool runs
legitimate admin activity
legitimate administration activities
legitimate administrator or user enumerates local users for legitimate reason
legitimate powershell scripts that make use of these functions.
legitimate use of psloglist by an administrator
other programs that use these command line option and accepts an 'all' parameter
some false positives may arise in some environment and this may require some tuning. add additional filters or reduce level depending on the level of noise
unlikely
verify whether the user identity should be using the sts `getcalleridentity` api operation. if known behavior is causing false positives, it can be exempted from the rule.
vulnerability scanners or system administration tools may also trigger this detection. filter as needed.