Rule Info
Name
Live Kernel Dump via CommandLine
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects live kernel dumps initiated via the command line.
While kernel dumps are not inherently malicious, these dumps can be accessed
to read sensitive process memory such as LSASS without opening a direct process
handle, bypassing traditional process-access based detections.
Date
2026-08-10 00:00:00
Modified
None
Id
f2d1e8b3-c5a4-4f7e-9b2d-1a3c6e8f0d5b
Tags
attack.credential-access attack.t1003.001
Type
Nextron Sigma feed only (private)
