LoFP LoFP / legitimate use of procdump by a developer or administrator

Techniques

Sample rules

Procdump Execution

Description

Detects usage of the SysInternals Procdump utility

Detection logic

condition: selection
selection:
  Image|endswith:
  - \procdump.exe
  - \procdump64.exe