LoFP LoFP / t1557

t1557

TitleTags
admins use packet captures for troubleshooting, performance monitoring, or security investigations. verify against change management. filter known admin accounts during maintenance windows.
automatic isatap configuration in some windows deployments
certain applications may install root certificates for the purpose of inspecting ssl traffic.
custom or portable notepad++ installations in non-standard directories.
ipv6 transition projects and network infrastructure changes
legitimate administrative use
legitimate files with these rare hacktool names
legitimate isatap router configuration in enterprise environments
legitimate update processes creating temporary files in unexpected locations.
legitimate use of the impacket tools
legitimate webproxy settings modification
legitimate windivert driver usage
network administrators configuring dual-stack networking
other legitimate query to official domains not listed in the filter, needing tuning.
private hosted zones may be legitimately associated with vpcs by network or infrastructure administrators. verify whether the user identity, user agent, and source ip address align with expected administrative behavior. known and authorized associations may be exempted to reduce noise.
some legitimate network misconfigurations or proxy issues causing unexpected dns queries.
this search might be prone to high false positives if dhcp snooping has been incorrectly configured or in the unlikely event that the dhcp server has been moved to another network interface.
uncommon but legitimate windows administrator or software tasks that make use of the encrypting file system rpc calls. verify if this is common activity (see description).
unknown
unlikely
unlikely. except due to misconfigurations