// Investigation
Hunt console
Structured search across the normalised event store. Terms combine with AND; prefix a value with ! to negate it.
hunt.queryREADY
to run
Result profile
1
event matches
Severity
- Critical1
- High0
- Medium0
- Low0
- Info0
Applied filters
- parent = powershell.exe
Matches
Newest first.
| Timestamp (UTC) | Severity | Event type | User | Source IP | Message |
|---|---|---|---|---|---|
| Critical | Credential Access | jsmith | — | Process memory of lsass.exe dumped to disk via comsvcs.dll MiniDump |