動作
非法入侵 #684
已結束ULPU-WG-PC-0019
開始日期:
2024-02-19
完成日期:
2024-02-29
完成百分比:
100%
預估工時:
概述
Description
A suspicious process read lsass memory. Adversaries often use this to steal credentials. If credentials were dumped, change your passwords and review the process tree.
Command line
"C:\Program Files\Cybereason ActiveProbe\minionhost.exe" -p 4916 -rc a568ecb5-1d1f-44df-93c4-f6a5ffbc99b1 -t 384
動作