a new Sigma rule to detect critical errors involving the lsass.exe process and WLDAP32.dll module in Windows Application Logs (EventID 1000). This rule helps identify potential exploitation attempts or system instability caused by crashes in critical Windows processes.
-
Notifications
You must be signed in to change notification settings - Fork 0
a new Sigma rule to detect critical errors involving the lsass.exe process and WLDAP32.dll module in Windows Application Logs (EventID 1000). This rule helps identify potential exploitation attempts or system instability caused by crashes in critical Windows processes.
cocopollo/sigma
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
About
a new Sigma rule to detect critical errors involving the lsass.exe process and WLDAP32.dll module in Windows Application Logs (EventID 1000). This rule helps identify potential exploitation attempts or system instability caused by crashes in critical Windows processes.
Resources
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published