LoFP LoFP / t1557

t1557

TitleTags
legitimate administrative use
legitimate files with these rare hacktool names
legitimate use of the impacket tools
legitimate windivert driver usage
none currently known
this search might be prone to high false positives if dhcp snooping has been incorrectly configured or in the unlikely event that the dhcp server has been moved to another network interface.
this search might be prone to high false positives if dhcp snooping or arp inspection has been incorrectly configured, or if a device normally sends many arp packets (unlikely).
this search might be prone to high false positives if you have malfunctioning devices connected to your ethernet ports or if end users periodically connect physical devices to the network.
uncommon but legitimate windows administrator or software tasks that make use of the encrypting file system rpc calls. verify if this is common activity (see description).
unlikely
unlikely. except due to misconfigurations