LoFP LoFP / T1204.003

T1204.003

TitleTags
new legitimate images during rollouts or blue/green deployments may appear until the allowlist is updated. coordinate with platform/devops teams to synchronize allowlist changes.
no false positives have been identified at this time.
security testing, approved red team exercises, or sanctioned diagnostics can trigger this analytic. coordinate allowlists and maintenance windows with platform/secops teams. please update a macro named `linux_offsec_tool_processes` that contains the list of known offensive tooling found on linux systems if your environment has additional known offensive tools that are not included in the macro.
when your development is spreaded in different time zones, applying this rule can be difficult.