LiveKD Kernel Memory Dump File Created

Rule Info

Name
LiveKD Kernel Memory Dump File Created
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects the creation of a file that has the same name as the default LiveKD kernel memory dump.
Reference
Internal Research
Date
2023-05-16 00:00:00
Modified
None
Id
814ddeca-3d31-4265-8e07-8cc54fb44903
Tags
attack.defense_evasion attack.privilege_escalation DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
github-actions[bot]
Merge PR #4791 from @nasbench - Promote older rules status from `experimental` to `test`
2024-04-01
Nasreddine Bencherchali
feat: multiple updates and new rules (#4242)
2023-05-17