Skip to content

<<< Hide Navigation Hide TOC >>>

Process Access via TrolleyExpress Exclusion (4c0aaedc-154c-4427-ada0-d80ef9c9deb6)

Detects a possible process memory dump that uses the white-listed Citrix TrolleyExpress.exe filename as a way to dump the lsass process memory