LoFP LoFP / t1136.002

t1136.002

TitleTags
legitimate administrative script
legitimate administrators might create an \"esx admins\" group for valid reasons. verify that the group creation is authorized and part of normal administrative tasks. consider the context of the action, such as the user performing it and any related activities.
legitimate administrators might create, delete, or modify an \"esx admins\" group for valid reasons. verify that the group changes are authorized and part of normal administrative tasks. consider the context of the action, such as the user performing it and any related activities.
legitimate administrators might create, delete, or modify an a privileged group for valid reasons. verify that the group changes are authorized and part of normal administrative tasks. consider the context of the action, such as the user performing it and any related activities.
some legitimate administrative activities during domain controller promotions or system updates may trigger this rule. filter alerts originating from authorized it personnel or approved change management processes.
unknown
unlikely