Threat Research

    Detects the loading of EvtMuteHook.dll, a critical component of SharpEvtHook, a tool used to manipulate Windows event logs....
    Detects the use of CoercedPotato, a tool designed for privilege escalation....
    Detects the use of the CreateMiniDump tool, commonly used to dump the LSASS process memory for credential extraction on an attacker’s machine....
    Looking for Something?
    Threat Research Categories:
    Tags