LoFP LoFP / rare legitimate files with similar filename structure

Techniques

Sample rules

SafetyKatz Default Dump Filename

Description

Detects default lsass dump filename from SafetyKatz

Detection logic

condition: selection
selection:
  TargetFilename|endswith: \Temp\debug.bin