Critically, he argued that the use of various tools should be instantly flagged as concerning. āInstrument Task Scheduler, PsExec, PsPasswd, and net user are highārisk signals. These are the insiderās equivalent of lockpicks,ā he said. āThey should generate behavioral alerts when used at scale, offāhours, or from unusual hosts.ā
Levine also suggested extensive system monitoring. āIf someone is RDPāing into a domain controller at 7:48 a.m. and creating 16 scheduled tasks, you should have a videoālike audit trail.ā
Paul Furtado, a distinguished VP analyst at Gartner, said he encourages clients to make sure that no single admin can cause this kind of damage.Ā
