LoFP LoFP / legitimate disabling of crashdumps

Techniques

Sample rules

CrashControl CrashDump Disabled

Description

Detects disabling the CrashDump per registry (as used by HermeticWiper)

Detection logic

condition: selection
selection:
  Details: DWORD (0x00000000)
  TargetObject|contains: SYSTEM\CurrentControlSet\Control\CrashControl