Suspicious Kernel Dump Using Dtrace — Detection Rule

Detects suspicious way to dump the kernel on Windows systems using dtrace.exe, which is available on Windows systems since Windows 10 19H1

Read the full analysis on IntelFusions