Potential Credential Dumping Attempt Using New NetworkProvider - REG — Detection Rule

Detects when an attacker tries to add a new network provider in order to dump clear text credentials, similar to how the NPPSpy tool does it

Read the full analysis on IntelFusions