LoFP LoFP / t1140

t1140

TitleTags
a legitimate forwarding rule.
actual mailbox rules that are moving items based on their workflow.
administrative script libraries
automated tools such as jenkins may encode or decode files as part of their normal behavior. these events can be filtered by the process executable or username values.
false positives depend on scripts and administrative tools used in the monitored environment
legitimate administration activities
legitimate powershell scripts which makes use of compression and encoding.
legitimate powershell scripts which makes use of encryption.
legitimate software that uses these patterns
typically seen used to `encode` files, but it is possible to see legitimate use of `decode`. filter based on parent-child relationship, file paths, endpoint or user.
unlikely
unlikely, because no sane admin pings ip addresses in a hexadecimal form