LoFP LoFP / msmpeng might crash if the \"c:\\" partition is full

Techniques

Sample rules

Microsoft Malware Protection Engine Crash - WER

Description

This rule detects a suspicious crash of the Microsoft Malware Protection Engine

Detection logic

condition: selection
selection:
  Data|contains|all:
  - MsMpEng.exe
  - mpengine.dll
  EventID: 1001
  Provider_Name: Windows Error Reporting

Microsoft Malware Protection Engine Crash

Description

This rule detects a suspicious crash of the Microsoft Malware Protection Engine

Detection logic

condition: selection
selection:
  Data|contains|all:
  - MsMpEng.exe
  - mpengine.dll
  EventID: 1000
  Provider_Name: Application Error