LoFP LoFP / t1557

t1557

TitleTags
legitimate administrative use
legitimate files with these rare hacktool names
legitimate use of the impacket tools
legitimate windivert driver usage
this search might be prone to high false positives if dhcp snooping has been incorrectly configured or in the unlikely event that the dhcp server has been moved to another network interface.
uncommon but legitimate windows administrator or software tasks that make use of the encrypting file system rpc calls. verify if this is common activity (see description).
unlikely
unlikely. except due to misconfigurations