Renamed ProcDump Execution — Detection Rule

Detects the execution of a renamed ProcDump executable. This often done by attackers or malware in order to evade defensive mechanisms.

Read the full analysis on IntelFusions