LoFP LoFP / t1135

t1135

TitleTags
an single endpoint accessing windows administrative shares across a large number of endpoints is not common behavior. possible false positive scenarios include but are not limited to vulnerability scanners, administration systems and missconfigured systems.
an single endpoint requesting a large number of kerberos service tickets is not common behavior. possible false positive scenarios include but are not limited to vulnerability scanners, administration systems and missconfigured systems.
legitimate administrative use
legitimate powershell scripts that make use of these functions.
security teams may leverage powerview proactively to identify and remediate sensitive file shares. filter as needed.
system administrators may use looks like net.exe or \"dir commandline\" for troubleshooting or administrations tasks. however, this will typically come only from certain users and certain systems that can be added to an allow list.
tools with similar commandline (very rare)
vulnerability scanners or system administration tools may also trigger this detection. filter as needed.