Update sysmon_lsass_memdump.yml
This commit is contained in:
@@ -19,9 +19,9 @@ detection:
|
||||
selection:
|
||||
TargetImage: 'C:\windows\system32\lsass.exe'
|
||||
GrantedAccess: '0x1fffff'
|
||||
CallTrace:
|
||||
- '*dbghelp.dll*'
|
||||
- '*dbgcore.dll*'
|
||||
CallTrace|contains:
|
||||
- 'dbghelp.dll'
|
||||
- 'dbgcore.dll'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- unknown
|
||||
|
||||
Reference in New Issue
Block a user