LoFP
/
t1529
t1529
Title
Tags
administrator may execute this commandline to trigger shutdown or restart the host machine.
t1529
endpoint
splunk
administrator may execute this commandline to trigger shutdown, logoff or restart the host machine.
t1529
endpoint
splunk
false positives will be present based on many factors. tune the correlation as needed to reduce too many triggers.
t1003
t1012
t1016
t1033
t1049
t1059
t1069
t1082
t1112
t1115
t1222
t1529
t1548
t1552
endpoint
splunk
legitimate administration activities
t1007
t1016
t1018
t1033
t1037
t1037.005
t1040
t1046
t1053
t1053.002
t1053.003
t1059
t1059.012
t1069
t1069.001
t1070
t1070.002
t1070.004
t1078
t1078.003
t1082
t1087
t1087.001
t1090
t1098
t1105
t1136
t1136.001
t1140
t1201
t1518
t1518.001
t1529
t1546
t1546.014
t1548
t1548.001
t1552
t1552.001
t1553
t1553.004
t1555
t1555.001
t1562
t1562.004
t1564
t1564.002
t1565
t1565.001
t1592
t1592.004
linux
macos
windows
sigma
legitimate administrators may run these commands, though rarely.
t1495
t1529
t1565
t1565.001
cisco
sigma
legitimate adminstrative usage of this functionality will trigger this detection.
t1021.007
t1072
t1105
t1202
t1484
t1529
t1562.001
t1562.004
azure tenant
splunk