LoFP LoFP / t1087.001

t1087.001

TitleTags
administrative activity
another tool that uses the command line switches of psloglist
commonly run by administrators
inventory tool runs
legitimate administration activities
legitimate administrator or user enumerates local users for legitimate reason
legitimate use of psloglist by an administrator
other programs that use these command line option and accepts an 'all' parameter
some false positives may arise in some environment and this may require some tuning. add additional filters or reduce level depending on the level of noise
unknown