LoFP LoFP / T1590.005

T1590.005

TitleTags
filter internet browser application to minimize the false positive of this detection.
internal scripts or agents performing network checks may query ip geolocation services. tune by excluding known tools or adding internal allowlists for destination domains or process names and commandlines.
legitimate sequences occur during troubleshooting, health checks, upgrades, audits, or automation scripts. verify against change management. filter known admin accounts, trusted management stations, or adjust threshold based on baseline.
no false positives have been identified at this time.