Windows LiveKD Kernel Memory Dump Attempt via "-m" Flag

Flags LiveKD executions with the "-m" option that may trigger kernel memory dumping on Windows.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-16
Updated
2026-07-30

What it detects

This rule identifies execution of Sysinternals LiveKD (livekd.exe or livekd64.exe) when the command line includes the "-m" flag, which can be used to dump kernel memory. Dumping kernel memory can expose sensitive data and may be used for stealthy credential or forensic discovery by an attacker. It relies on process creation telemetry capturing the executable path/name and full command line arguments on Windows.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.