![Back to home Valhalla Logo](/static/valhalla-logo.png)
Rule Info
Name
LiveKD Kernel Memory Dump File Created
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects the creation of a file that has the same name as the default LiveKD kernel memory dump.
Reference
Internal Research
Date
2023-05-16 00:00:00
Modified
None
Id
814ddeca-3d31-4265-8e07-8cc54fb44903
Tags
attack.defense_evasion attack.privilege_escalation DEMO
Type
Community Rule
Link to Public Repo