LoFP LoFP / t1134

t1134

TitleTags
administrative activity
administrative scripts using explicit credentials from non-standard paths
anti-virus
break-glass admin tooling, security scanners, or approved controllers that legitimately use impersonation with privileged targets may match if not covered by exclusions. map expected callers and expand `not user.name` filters as needed for your environment.
commandlines containing components like cmd accidentally
jobs and services started with cmd
migration of an account into a new domain
monitoring activity
runas usage from user-installed applications outside program files
runas usage spawning one of the listed binaries under a different account
scripts and administrative tools used in the monitored environment
unknown
unlikely