LoFP LoFP / t1608

t1608

TitleTags
benign files can trigger signatures in the built-in virus protection
development or testing environments that simulate external key management scenarios. even in these cases, such activity is typically infrequent and should not add significant noise.
legitimate email service automation may attach amazonsesfullaccess to a service account. validate the target iam entity against known email automation roles and ci/cd pipeline identities. because this is a new terms rule keyed on the calling identity, recurring attachments by the same automation will not re-alert within the 7-day history window; first-time attachments by administrators performing legitimate setup may still trigger and should be validated against change management records.
legitimate use cases for imported key material are rare, but may include, organizations with hybrid cloud architectures that import external key material for compliance requirements.
legitimate users may create sns topics for legitimate purposes. ensure that the creation is authorized before taking action.
scripts or tools that download attachments from these domains (onenote, outlook 365)
unknown