LoFP LoFP / t1134

t1134

TitleTags
administrative activity
anti-virus
commandlines containing components like cmd accidentally
false positives may be generated by administrators installing benign applications using run-as/elevation.
jobs and services started with cmd
migration of an account into a new domain
monitoring activity
scripts and administrative tools used in the monitored environment
unlikely