Tag
high
advisory
Detection of LSASS Memory Dumping via Command Line Keywords
1 rule 1 TTPDetection of credential access attempts targeting the Local Security Authority Subsystem Service (LSASS) process via command-line arguments indicative of memory dump creation.
credential-access
windows
security-monitoring
1r
1t
medium
advisory
Detection of Windows Defender Malware and Suspicious Activity Events
1 ruleThis brief outlines the monitoring of Windows Defender Antimalware events that indicate confirmed malware detections or suspicious system behavior.
windows
security-monitoring
informational
1r