Potential SysInternals ProcDump Evasion (79b06761-465f-4f88-9ef2-150e24d3d737)
Detects uses of the SysInternals ProcDump utility in which ProcDump or its output get renamed, or a dump file is moved or copied to a different name
Detects uses of the SysInternals ProcDump utility in which ProcDump or its output get renamed, or a dump file is moved or copied to a different name