LoFP LoFP / valid user connecting using rdp

Techniques

Sample rules

Unsigned Image Loaded Into LSASS Process

Description

Loading unsigned image (DLL, EXE) into LSASS process

Detection logic

condition: selection
selection:
  Image|endswith: \lsass.exe
  Signed: 'false'