LoFP LoFP / t1553

t1553

TitleTags
certain applications may install root certificates for the purpose of inspecting ssl traffic.
files that are interacted with that have these extensions legitimately
help desk or it may need to manually add a corporate root ca on occasion. need to test if gpo push doesn't trigger fp
legitimate activities
legitimate administration activities
legitimate administrative script
legitimate applications packaged with advanced installer using package support framework
legitimate installation of unsigned packages for legitimate purposes such as development or testing
legitimate powershell scripts
legitimate sip being registered by the os or different software.
legitimate usage of sdelete
not commonly run by administrators. also whitelist your known good certificates
some legitimate applications installation which have been missed from filtering can generate fps, thus baselining and tuning is recommended before deploying to production
unknown