LoFP LoFP / t1505

t1505

TitleTags
admin activity
administrative activity
bedrock agent and action group changes are common during legitimate development, prompt tuning, and ci/cd deployments. verify whether the user identity, user agent, and/or source ip should be modifying agents in your environment, and confirm a corresponding change request exists. automation roles (iac pipelines, deployment tooling) may routinely call these apis and can be exempted from the rule if they generate false positives.
crazy web applications
developers or administrators creating bedrock agents interactively using personal iam user credentials. this is the intended detection surface — validate the identity against known developer accounts and confirm the agent configuration (instruction, action groups, model) matches a known project.
false positives are expected to be very rare due to the specific nature of this rule. legitimate application deployments typically do not involve multipart form uploads to .action endpoints followed immediately by jsp file creation in webapps directories. however, custom deployment scripts or automated testing tools that simulate file uploads could potentially trigger this alert. review the source ip, user agent, uploaded file content, timing, and deployment schedules to validate if the activity is authorized. standard package manager operations are already excluded from detection.
files generated during installation will generate a lot of noise, so the rule should only be enabled after the fact.
inventory and monitoring activity
legitimate administrative use
legitimate administrator activity
legitimate administrator or developer creating legitimate executable files in a web application folder
legitimate administrators may run these commands
legitimate application and websites that use windows paths in their url
legitimate applications
legitimate installations of exchange transportagents. assemblypath is a good indicator for this.
legitimate platform, ml, or application teams may associate or update knowledge bases on bedrock agents as part of normal development, onboarding, or rag pipeline changes. verify that the actor identity, user agent, and source ip correspond to expected automation or authorized engineers, and that the associated knowledge base is an approved, organization-owned resource. if known behavior is causing false positives, it can be exempted from the rule.
network monitoring or management products may have a web server component that runs shell commands as part of normal behavior.
particular web applications may spawn a shell process legitimately
security audits, maintenance, and network administrative scripts may trigger this alert only when parent context, child identity, command scope, service identity, and available artifact or destination evidence align to the same bounded workflow.
this rule was tuned using the following baseline: https://raw.githubusercontent.com/microsoft/css-exchange/main/security/baselines/baseline_15.2.792.5.csv from microsoft. depending on version, consult https://github.com/microsoft/css-exchange/tree/main/security/baselines to help determine normalcy.
unknown
unknown as it may vary from organisation to organisation how admins use to install iis modules
unlikely
user searches in search boxes of the respective website
vulnerability scanners
web applications that invoke linux command line tools
web applications that use the same url parameters as regeorg
web servers or administrators may create php files in the wordpress plugin directory during maintenance.
web sites like wikis with articles on os commands and pages that include the os commands in the urls