Access LSASS Memory For Dump Creation

Description

Detect memory dumping of the LSASS process.

   Help

Access LSASS Memory For Dump Creation Help

This search requires Sysmon Logs and a Sysmon configuration, which includes EventCode 10 for lsass.exe. This search uses an input macro named sysmon. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives.

   Search

Open in Search