Rule Info
Name
PowerShell Live Kernel Dump
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects PowerShell scripts or commands that create live kernel dumps.
While live kernel dumps are a legitimate diagnostic mechanism, they are increasingly
abused by threat actors to read sensitive process memory such as LSASS without opening
a direct process handle, bypassing traditional process-access based detections.
Date
2026-08-10 00:00:00
Modified
None
Id
b8f1e3c2-d4a7-4b9e-8c5d-2f3a1b0e7d6c
Tags
attack.credential-access attack.t1003.001
Type
Nextron Sigma feed only (private)
