LoFP LoFP / t1562.004

t1562.004

TitleTags
a network operator or systems administrator may utilize an automated or manual execution of this firewall rule that may generate false positives. filter as needed.
admin activity
administrator may do this commandline for auditing and testing purposes. in this scenario filter is needed.
administrator may modify or delete firewall configuration.
administrator or network operator can use this application for automation purposes. please update the filter macros to remove false positives.
administrator scripts or activity.
firewall being modified or deleted may be performed by a system administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
firewall modified or deleted from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
legitimate admin activity
legitimate admin changes, group policy updates, software installs, security tools, and automated scripts can trigger false positives for event id 4946.
legitimate admin delete, group policy updates, software installs, security tools, and automated scripts can trigger false positives for event id 4948.
legitimate administration activities
legitimate administration activity
legitimate adminstrative usage of this functionality will trigger this detection.
legitimate ports redirect
network administrators
rule collections (application, nat, and network) being modified or deleted may be performed by a system administrator. verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
rule collections (application, nat, and network) modified or deleted from unfamiliar users should be investigated. if known behavior is causing false positives, it can be exempted from the rule.
software installations
software installations and removal
some vpn applications are known to launch netsh.exe. outside of these instances, it is unusual for an executable to launch netsh.exe and run commands.