Skip to content

a new Sigma rule to detect critical errors involving the lsass.exe process and WLDAP32.dll module in Windows Application Logs (EventID 1000). This rule helps identify potential exploitation attempts or system instability caused by crashes in critical Windows processes.

Notifications You must be signed in to change notification settings

cocopollo/sigma

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 

Repository files navigation

sigma

a new Sigma rule to detect critical errors involving the lsass.exe process and WLDAP32.dll module in Windows Application Logs (EventID 1000). This rule helps identify potential exploitation attempts or system instability caused by crashes in critical Windows processes.

About

a new Sigma rule to detect critical errors involving the lsass.exe process and WLDAP32.dll module in Windows Application Logs (EventID 1000). This rule helps identify potential exploitation attempts or system instability caused by crashes in critical Windows processes.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published