Credential Dumping Attempt Via Svchost (174afcfa-6e40-4ae9-af64-496546389294)
Detects when a process tries to access the memory of svchost to potentially dump credentials.
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Abuse Elevation Control Mechanism - T1548 (67720091-eee3-4d2d-ae16-8264567f6f5b) | Attack Pattern | Credential Dumping Attempt Via Svchost (174afcfa-6e40-4ae9-af64-496546389294) | Sigma-Rules | 1 |