LoFP LoFP / t1222.001

t1222.001

TitleTags
administrative activity
administrators or administrative scripts may use this application. filter as needed.
edge cases may exist in environments where this command is used for legitimate purposes. however, such usage is expected to be uncommon. it is recommended to investigate any occurrences of this command, and apply filters as necessary.
general usage of group policy will trigger this detection, also please not gpos modified using tools such as sharpgpoabuse will not generate the ad audit events which enable this detection.
if key credentials are regularly assigned to users, these events will need to be tuned out.
legitimate usage, investigate the parent process and context to determine if benign.
no false positives have been identified at this time.
no false positives have been identified at this time. filter as needed.
no false positives have been identified at this time. should be identified and understood.
scripts created by developers and admins
some applications and users may legitimately use attrib.exe to interact with the files.
unknown