LoFP LoFP / t1568

t1568

TitleTags
a newly installed program or one that runs rarely as part of a monthly or quarterly workflow could trigger this alert. network activity that occurs rarely, in small quantities, can trigger this alert. possible examples are browsing technical support or vendor networks sparsely. a user who visits a new or unique web destination may trigger this alert.
legitimate use of ngrok
legitimate use of the ngrok service.
software downloads
this rule could identify benign domains that are formatted similarly to fin7's command and control algorithm. alerts should be investigated by an analyst to assess the validity of the individual observations.
this rule should be tailored to either exclude systems, as sources or destinations, in which this behavior is expected.
this rule should be tailored to exclude systems, either as sources or destinations, in which this behavior is expected.