mirror of
				https://github.com/LOLBAS-Project/LOLBAS
				synced 2025-11-04 10:39:56 +01:00 
			
		
		
		
	Update Sqldumper.yml (#439)
This commit is contained in:
		@@ -21,6 +21,7 @@ Commands:
 | 
			
		||||
Full_Path:
 | 
			
		||||
  - Path: C:\Program Files\Microsoft SQL Server\90\Shared\SQLDumper.exe
 | 
			
		||||
  - Path: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis\AS OLEDB\140\SQLDumper.exe
 | 
			
		||||
  - Path: C:\Program Files\Microsoft Power BI Desktop\bin\SqlDumper.exe
 | 
			
		||||
Detection:
 | 
			
		||||
  - Sigma: https://github.com/SigmaHQ/sigma/blob/683b63f8184b93c9564c4310d10c571cbe367e1e/rules/windows/process_creation/proc_creation_win_lolbin_susp_sqldumper_activity.yml
 | 
			
		||||
  - Elastic: https://github.com/elastic/detection-rules/blob/f6421d8c534f295518a2c945f530e8afc4c8ad1b/rules/windows/credential_access_lsass_memdump_file_created.toml
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user