Live Memory Dump Using Powershell (cd185561-4760-45d6-a63e-a51325112cae)
Detects usage of a PowerShell command to dump the live memory of a Windows machine
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Live Memory Dump Using Powershell (cd185561-4760-45d6-a63e-a51325112cae) | Sigma-Rules | OS Credential Dumping - T1003 (0a3ead4e-6d47-4ccb-854c-a6a4f9d96b22) | Attack Pattern | 1 |