Azure-Sentinel/Hunting Queries/SecurityEvent/SuspectedLSASSDump.yaml

4 строки
304 B
YAML

id: 2841b25a-54d1-4c2a-8d06-3e73ef3b6dbc
name: Suspected LSASS Dump
description: |
'As part of content migration, this file is moved to new location. you can find here: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Windows%20Security%20Events/Hunting%20Queries/SuspectedLSASSDump.yaml'