LoFP LoFP / t1222

t1222

TitleTags
access level modifications may be done by a system or network administrator. verify whether the username, hostname, and/or resource name should be making changes in your environment. access level modifications from unfamiliar users or hosts should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
administrative activity
administrator interacting with immutable files (e.g. for instance backups).
blob permissions may be modified by system administrators. verify that the configuration change was expected. exceptions can be added to this rule to filter expected behavior.
certain programs or applications may modify files or change ownership in writable directories. these can be exempted by username.
legitimate usage, investigate the parent process and context to determine if benign.
scripts created by developers and admins
some false positives are to be expected. apply additional filters as needed before pushing to production.
storage bucket permissions may be modified by system administrators. verify that the configuration change was expected. exceptions can be added to this rule to filter expected behavior.
unknown
user interacting with files permissions (normal/daily behaviour).