Unsigned Image Loaded By LSASS


This search detects loading of unsigned images by LSASS. Deprecated because too noisy.


Unsigned Image Loaded By LSASS Help

This search needs Sysmon Logs with a sysmon configuration, which includes EventCode 7 with lsass.exe. This search uses an input macro named sysmon. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives.


Open in Search