LoFP LoFP / t1490

t1490

TitleTags
admin activities or installing related updates may do a sudden stop to list of services we monitor.
administrators may modify the boot configuration ignore failure during testing and debugging.
administrators may modify the boot configuration.
administrators within an aws organization structure may legitimately suspend object versioning. ensure that this behavior is not part of a legitimate operation before taking action.
aws administrator legitimately disabling bucket versioning
backup scenarios using the commandline
certain utilities that delete files for disk cleanup or administrators manually removing backup files.
in some cases admin can disable systemrestore on a machine.
it is possible that an aws administrator has legitimately disabled versioning on certain buckets to avoid costs.
landesk ldclient ivanti-psmodule (ps encodedcommand)
legitimate activities
legitimate administrator activity
legitimate administrator deletes shadow copies using operating systems utilities for legitimate reason
legitimate administrators may run these commands
legitimate backup activity from administration scripts and software.
legitime usage
network admin can resize the shadowstorage for valid purposes.
unlikely
vssadmin.exe and wmic.exe are standard applications shipped with modern versions of windows. they may be used by administrators to legitimately delete old backup copies, although this is typically rare.