LoFP LoFP / t1557

t1557

TitleTags
a user legitimately enrolling several devices in a short window (for example, a new laptop and phone during onboarding, or re-registering a device after a wipe) can produce three or more registrations. validate against the user's device inventory and onboarding activity, and consider raising the threshold or tightening the window if benign multi-device enrollment is common in the environment.
a user simultaneously enrolling multiple workspace-aware apps on a new device (e.g., first-time setup of gmail, drive, calendar, and meet on a new laptop in a short window) may produce three or more distinct device ids in a minute. validate by checking whether the burst is tied to a fresh device or onboarding event.
automatic isatap configuration in some windows deployments
bulk provisioning workflows, autopilot/mdm rollouts, or device-management tooling that registers devices on behalf of users may generate multiple registrations across many users at once. suppress during planned rollout windows.
carrier-grade nat or load-balanced corporate egress that occasionally routes through alternate asns.
certain applications may install root certificates for the purpose of inspecting ssl traffic.
custom or portable notepad++ installations in non-standard directories.
google's risk engine occasionally flags legitimate sign-ins as suspicious when the user is on a new device, on a vpn egress that geo-resolves to a different region, or after extended time away. validate by checking the user's recent sign-in history and confirming with the user.
ipv6 transition projects and network infrastructure changes
legacy internal applications, industrial control systems, or embedded devices may still require deprecated tls versions or weak ciphers. exclude known legacy destination ips or subnets after validation.
legitimate administrative use
legitimate files with these rare hacktool names
legitimate first-time use of a new network: isp change, new vpn provider, travel to a region using a different mobile carrier, new home office.
legitimate isatap router configuration in enterprise environments
legitimate update processes creating temporary files in unexpected locations.
legitimate use of the impacket tools
legitimate webproxy settings modification
legitimate windivert driver usage
major os upgrades or workspace client refreshes that re-attest several apps concurrently may also produce a burst. cross-reference against the user's known device os transitions.
network administrators configuring dual-stack networking
other legitimate query to official domains not listed in the filter, needing tuning.
private hosted zones may be legitimately associated with vpcs by network or infrastructure administrators. verify whether the user identity, user agent, and source ip address align with expected administrative behavior. known and authorized associations may be exempted to reduce noise.
some legitimate network misconfigurations or proxy issues causing unexpected dns queries.
uncommon but legitimate windows administrator or software tasks that make use of the encrypting file system rpc calls. verify if this is common activity (see description).
unknown
unlikely
unlikely. except due to misconfigurations
users on vpn or proxy egress that geo-resolves through a region distant from the user's physical location. mobile clients on cellular carrier networks that peer through regional hubs may geo-resolve to a different region than the user's physical location. corporate aws workspaces / vdi deployments where employees interactively sign in from a cloud-provider asn.