LoFP LoFP / t1558

t1558

TitleTags
administration activity
first-time or infrequent access to legacy services, cross-platform integrations, and inter-domain trust activity may legitimately establish a new requester-to-service relationship using rc4 encryption.
http traffic on a non standard port. verify that the destination ip address is not related to a domain controller.
legacy applications.
legitimate command line usage by administrators or security tools.
legitimate use of the library for administrative activity
normal enterprise spn requests activity
service accounts used on legacy systems (e.g. netapp)
unknown
unlikely
web browsers and third party application might generate similar activity. an initial baseline is required.
windows domains with dfl 2003 and legacy systems