LoFP LoFP / t1222

t1222

TitleTags
admin changing file permissions.
administrative activity
administrator interacting with immutable files (e.g. for instance backups).
administrators may use this command. filter as needed.
administrators or administrative scripts may use this application. filter as needed.
blob permissions may be modified by system administrators. verify that the configuration change was expected. exceptions can be added to this rule to filter expected behavior.
certain programs or applications may modify files or change ownership in writable directories. these can be exempted by username.
false positives will be present based on many factors. tune the correlation as needed to reduce too many triggers.
scripts created by developers and admins
storage bucket permissions may be modified by system administrators. verify that the configuration change was expected. exceptions can be added to this rule to filter expected behavior.
takeown.exe is a normal windows application that may used by network operator.
user interacting with files permissions (normal/daily behaviour).