LoFP LoFP / t1546

t1546

TitleTags
adding new users or groups to the adminsdholder acl is not usual. filter as needed
admin activity
admin or user activity are expected to generate some false positives
changes to the shell profile tend to be noisy, a tuning per your environment will be required.
custom windows error reporting debugger or applications restarted by werfault after a crash.
dell computers on some versions register an event consumer that is known to cause false positives when brightness is changed by the corresponding keyboard button
dell power manager (c:\program files\dell\powermanager\dpmpowerplansetup.exe)
exclude legitimate (vetted) use of wmi event subscription in your network
gpo
lambda function owners may legitimately update the function policy to allow public invocation.
legitimate administration activities
legitimate administration and tuning scripts that aim to add functionality to a user powershell session
legitimate administrative use
legitimate administrator sets up autorun keys for legitimate reason
legitimate applications making use of this feature for compatibility reasons
legitimate applications registering their binary from on of the suspicious locations mentioned above (tune it)
legitimate custom shim installations will also trigger this rule
legitimate event consumers
legitimate helper added by different programs and the os
legitimate modification of screensaver
legitimate powershell scripts
legitimate software creating script event consumers
legitimate use
legitimate use of the dll.
legitimate use of the profile by developers or administrators
legitimate user shell modification activity.
maybe some system utilities in rare cases use linking keys for backward compatibility
system administrator creating powershell profile manually
trusted applications for managing calendars and reminders.
unknown (data set is too small; further testing needed)
unlikely
user genuinely creates a vb macro for their email