LoFP LoFP / t1219

t1219

TitleTags
authorized github repository with no malicious workflow actions.
authorized remote file uploads by it administrators
depending on the environment the rule might require some initial tuning before usage to avoid fp with third party applications
environments that legitimately use meshagent
false positives can be found in environments using meshagent for remote management, analysis should prioritize the grandparent process, meshagent.exe, and scrutinize the resulting child processes triggered by any suspicious interactive commands directed at the target host.
host connections not using host fqdn.
host connections to external legitimate domains.
host connections to valid domains, exclude these.
if the script being executed make use of any of the utilities mentioned in the detection then they should filtered out or allowed.
legitimate activity of system administrators
legitimate administrators or incident responders might use velociraptor to execute scripts or tools. however, the combination of velociraptor spawning these specific processes with these command lines is suspicious. tuning may be required to exclude known administrative actions or specific scripts.
legitimate atera agent installation
legitimate deployment of anydesk
legitimate incoming connections (e.g. sysadmin activity). most of the time i would expect outgoing connections (initiated locally).
legitimate openedr file management operations
legitimate piping of the password to anydesk
legitimate system administrator deploying tacticalrmm
legitimate usage of the tool
legitimate use
legitimate use of anydesk from a non-standard folder
legitimate use of openedr for remote command execution
legitimate use of quick assist in the environment.
legitimate use of the tool
legitimate use of visual studio code tunnel
legitimate uses of teamviewer in an organisation
likelihood is related to how often the paths are used in the environment
likely with legitimate usage of \".rdp\" files
likely with other browser software. apply additional filters for any other browsers you might use.
software deployment through openedr console
some fp could occur with similar tools that uses the same command line '--set-password'
unknown
unknown binary names of teamviewer
unlikely
vnc connections may be made directly to linux cloud server instances but such connections are usually made only by engineers. vnc is less common than ssh or rdp but may be required by some work flows such as remote access and support for specialized software products or servers. such work-flows are usually known and not unexpected. usage that is unfamiliar to server or network owners can be unexpected and suspicious.
vnc connections may be received directly to linux cloud server instances but such connections are usually made only by engineers. vnc is less common than ssh or rdp but may be required by some work-flows such as remote access and support for specialized software products or servers. such work-flows are usually known and not unexpected. usage that is unfamiliar to server or network owners can be unexpected and suspicious.