LoFP LoFP / t1087.002

t1087.002

TitleTags
administrative activity
administrator activity
administrators configuring new users.
another tool that uses the command line switches of psloglist
authorized administrative activity
if source account name is not an admin then its super suspicious
inventory tool runs
legitimate admin activity
legitimate use of adexplorer by administrators creating .dat snapshots
legitimate use of psloglist by an administrator
other programs that use these command line option and accepts an 'all' parameter
some false positives may arise in some environment and this may require some tuning. add additional filters or reduce level depending on the level of noise
unknown