LoFP LoFP / rare legitimate files with similar filename structure

Techniques

Sample rules

HackTool - SafetyKatz Dump Indicator

Description

Detects default lsass dump filename generated by SafetyKatz.

Detection logic

condition: selection
selection:
  TargetFilename|endswith: \Temp\debug.bin