Techniques
Sample rules
LiveKD Kernel Memory Dump File Created
- source: sigma
- technicques:
Description
Detects the creation of a file that has the same name as the default LiveKD kernel memory dump.
Detection logic
condition: selection
selection:
TargetFilename: C:\Windows\livekd.dmp