Techniques
Sample rules
Windows Kernel Debugger Execution
- source: sigma
- technicques:
Description
Detects execution of the Windows Kernel Debugger “kd.exe”.
Detection logic
condition: selection
selection:
- Image|endswith: \kd.exe
- OriginalFileName: kd.exe