LoFP LoFP / legitimate mssql server actions

Techniques

Sample rules

Dumping Process via Sqldumper.exe

Description

Detects process dump via legitimate sqldumper.exe binary

Detection logic

condition: selection
selection:
  CommandLine|contains:
  - '0x0110'
  - 0x01100:40
  Image|endswith: \sqldumper.exe