LoFP LoFP / t1187

t1187

TitleTags
commands with all of these base64 encoded values are unusual in production environments. filter as needed.
creating a dns entry matching this pattern is very unusual in a production environment. filter as needed.
creating and deleting a dns server object within 30 seconds or less is unusual but not impossible in a production environment. filter as needed.
false positives have been limited when the anonymous logon is used for account name.
it's unlikely that a dns entry contains the specific structure used by this attack. filter as needed for your organization.
uncommon but legitimate windows administrator or software tasks that make use of the encrypting file system rpc calls. verify if this is common activity (see description).
unknown
unknown. feedback welcomed.