Dump LSASS Via Comsvcs DLL

Description

Detect the usage of comsvcs.dll for dumping the lsass process.

   Help

Dump LSASS Via Comsvcs DLL Help

You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints, to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model.

   Search

Open in Search