You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Detects suspicious uses of the SysInternals Procdump utility by using a special command line parameter in combination with the lsass.exe process. This way we're also able to catch cases in which the attacker has renamed the procdump executable.
Additional Details
Detail
Value
Type
Templated Match
Category
Credential Access
Apply Risk to Entities
device_hostname, device_ip, user_username
Signal Name
Suspicious Use of Procdump
Summary Expression
Suspicious Procdump usage on host: {{device_hostname}}