LoFP LoFP / t1529

t1529

TitleTags
administrator may execute this commandline to trigger shutdown or restart the host machine.
administrator may execute this commandline to trigger shutdown, logoff or restart the host machine.
false positives will be present based on many factors. tune the correlation as needed to reduce too many triggers.
legitimate administration activities
legitimate administrative activity modifying sysrq for debugging or recovery. please update the filter macros to remove false positives.
legitimate administrators may run these commands, though rarely.
legitimate adminstrative usage of this functionality will trigger this detection.
limited false positives in most environments, however tune as needed.
pods may be deleted by a system administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment. pods deletions by unfamiliar users or hosts should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
unknown