Title:Password Dumper Remote Thread in LSASS Status:stable Description:Detects password dumper activity by monitoring remote thread creation EventID 8 in combination with the lsass.exe process as TargetImage.
The process in field Process is the malicious program. A single execution can lead to hundreds of events.
References: -https://jpcertcc.github.io/ToolAnalysisResultSheet/details/WCE.htm Author: Thomas Patzke Date: 2017-02-19 modified:2021-06-21 Tags: