LoFP LoFP / t1134

t1134

TitleTags
administrative activity
administrators may create vbs or js script that use several tool as part of its execution. filter as needed.
anti-virus
commandlines containing components like cmd accidentally
domain mergers and migrations may generate large volumes of false positives for this analytic.
false positives may be generated by administrators installing benign applications using run-as/elevation.
it is possible legitimate applications will request access to winlogon, filter as needed.
jobs and services started with cmd
migration of an account into a new domain
migration of privileged accounts.
monitoring activity
scripts and administrative tools used in the monitored environment
some native binaries and browser applications may request sedebugprivilege. filter as needed.
this is a hunting search which provides verbose results against this endpoint. operator must consider things such as ip address, useragent and user(specially low privelege) and host to investigate possible attack.
unlikely