LoFP LoFP / t1490

t1490

TitleTags
admin activities or installing related updates may do a sudden stop to list of services we monitor.
administrator or troubleshooting activities may trigger this alert. investigate the process performing this action to determine if its a legitimate activity.
administrators may enable or disable this feature that may cause some false positive.
administrators may modify the boot configuration ignore failure during testing and debugging.
administrators may modify the boot configuration.
administrators within an aws organization structure may legitimately suspend object versioning. ensure that this behavior is not part of a legitimate operation before taking action.
aws administrator legitimately disabling bucket versioning
backup scenarios using the commandline
certain utilities that delete files for disk cleanup or administrators manually removing backup files.
in some cases admin can disable systemrestore on a machine.
it is possible that an aws administrator has legitimately disabled versioning on certain buckets to avoid costs.
landesk ldclient ivanti-psmodule (ps encodedcommand)
legitimate activities
legitimate administrator activity
legitimate administrator deletes shadow copies using operating systems utilities for legitimate reason
legitimate administrators may run these commands
legitimate backup activity from administration scripts and software.
legitime usage
network admin can resize the shadowstorage for valid purposes.
unlikely
vssadmin.exe and wmic.exe are standard applications shipped with modern versions of windows. they may be used by administrators to legitimately delete old backup copies, although this is typically rare.