Access LSASS Memory For Dump Creation
Detect memory dumping of the LSASS process.
This content has been mapped to the local saved search:
- IndexerLevel - Maximum memory utilisation per search [Remove]
Access LSASS Memory For Dump Creation Help
This search requires Sysmon Logs and a Sysmon configuration, which includes EventCode 10 for lsass.exe. This search uses an input macro named
Open in Search