LoFP LoFP / t1685.001

t1685.001

TitleTags
admin activity
administrator or administrator scripts might leverage the flags mentioned in the detection section. either way, it should always be monitored
administrator or backup activity
an unknown bug seems to trigger the windows \"svchost\" process to drop evtx files in the \"c:\windows\temp\" directory in the form \"<log_name\">_<uuid>.evtx\". see https://superuser.com/questions/1371229/low-disk-space-after-filling-up-c-windows-temp-with-evtx-and-txt-files
highly unlikely
legitimate administrative use
legitimate administrator activity
maintenance activity
other dlls with the same imphash
rare falsepositives may occur from legitimate administrators disabling specific event log for troubleshooting
scripts and administrative tools used in the monitored environment
the old auditpol utility isn't available by default on recent versions of windows as it was replaced by a newer version. the fp rate should be very low except for tools that use a similar flag structure
unknown
unlikely