LoFP LoFP / t1482

t1482

TitleTags
domain administrators may use this command-line utility for legitimate information gathering purposes.
legitimate admin activity
legitimate administration activity
legitimate administration use but user and host must be investigated
legitimate powershell scripts that make use of these functions.
legitimate use of adexplorer by administrators creating .dat snapshots
legitimate use of the utilities by legitimate user for legitimate reason
likely
other programs that use these command line option and accepts an 'all' parameter
powershell and windows command shell are often observed as legit child processes of the jetbrains teamcity service and may require further tuning.
some false positives may arise in some environment and this may require some tuning. add additional filters or reduce level depending on the level of noise
unknown