LoFP LoFP / t1557.001

t1557.001

TitleTags
commands with all of these base64 encoded values are unusual in production environments. filter as needed.
creating a dns entry matching this pattern is very unusual in a production environment. filter as needed.
creating and deleting a dns server object within 30 seconds or less is unusual but not impossible in a production environment. filter as needed.
it's unlikely that a dns entry contains the specific structure used by this attack. filter as needed for your organization.
legitimate files with these rare hacktool names
legitimate use of the impacket tools
legitimate windivert driver usage
uncommon but legitimate windows administrator or software tasks that make use of the encrypting file system rpc calls. verify if this is common activity (see description).
unknown
unlikely