LoFP LoFP / legitimate usage by software developers/testers

Techniques

Sample rules

Time Travel Debugging Utility Usage - Image

Description

Detects usage of Time Travel Debugging Utility. Adversaries can execute malicious processes and dump processes, such as lsass.exe, via tttracer.exe.

Detection logic

condition: selection
selection:
  ImageLoaded|endswith:
  - \ttdrecord.dll
  - \ttdwriter.dll
  - \ttdloader.dll

Time Travel Debugging Utility Usage

Description

Detects usage of Time Travel Debugging Utility. Adversaries can execute malicious processes and dump processes, such as lsass.exe, via tttracer.exe.

Detection logic

condition: selection
selection:
  ParentImage|endswith: \tttracer.exe