Unsigned Image Loaded By LSASS
Description
This search detects loading of unsigned images by LSASS. Deprecated because too noisy.
Content Mapping
This content is not mapped to any local saved search. Add mapping
Help |
---|
Unsigned Image Loaded By LSASS HelpThis search needs Sysmon Logs with a sysmon configuration, which includes EventCode 7 with lsass.exe. This search uses an input macro named |
Search |
---|
Open in Search |