PowerShell Live Kernel Dump

Rule Info

Name
PowerShell Live Kernel Dump
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects PowerShell scripts or commands that create live kernel dumps. While live kernel dumps are a legitimate diagnostic mechanism, they are increasingly abused by threat actors to read sensitive process memory such as LSASS without opening a direct process handle, bypassing traditional process-access based detections.
Date
2026-08-10 00:00:00
Modified
None
Id
b8f1e3c2-d4a7-4b9e-8c5d-2f3a1b0e7d6c
Tags
attack.credential-access attack.t1003.001
Type
Nextron Sigma feed only (private)

Rule History