LoFP LoFP / t1210

t1210

TitleTags
3rd party apache modules - https://bz.apache.org/bugzilla/show_bug.cgi?id=46185
files generated during installation will generate a lot of noise, so the rule should only be enabled after the fact.
legitimate processes may be spawned from the microsoft exchange server unified messaging (um) service. if known processes are causing false positives, they can be exempted from the rule.
legitimate use of quick assist in the environment.
legitimate use of the kubelet run/exec/attach/portforward endpoints via nodes/proxy is rare. administrative debugging tools that proxy exec through the api server may match; baseline and exclude verified operators.
monitoring and log-collection agents that run outside kube-system (for example a metrics agent in its own namespace) proxy to the kubelet on every scrape and will match repeatedly. add targeted exclusions for verified monitoring service accounts and namespaces after review.
this rule was tuned using the following baseline: https://raw.githubusercontent.com/microsoft/css-exchange/main/security/baselines/baseline_15.2.792.5.csv from microsoft. depending on version, consult https://github.com/microsoft/css-exchange/tree/main/security/baselines to help determine normalcy.
unknown
werfault.exe will legitimately spawn when dns.exe crashes, but the dns service is very stable and so this is a low occurring event. denial of service (dos) attempts by intentionally crashing the service will also cause werfault.exe to spawn.