Discovery Command - "net" localgroup administrators detected in mid server

JitendraT
Tera Expert

Hi Team,

 

Couple of mid-servers are triggering Discovery Command - "net" localgroup administrators. I want to confirm whether its legitimate activity or suspicious one.

I am not sure how/why this command has been triggered time to time as I couldn't find any related command in mid server logs. Any input would be helpful.

#mid-server commands

1 ACCEPTED SOLUTION
2 REPLIES 2

SDGrubeWasTaken
ServiceNow Employee
ServiceNow Employee

Did you ever find the root cause of this? Was it resolved?