Windows Process Creation: LiveKD Execution Suggesting Potential Memory Dumping

Detects launching LiveKD (livekd.exe/livekd64.exe) on Windows via image path or PE OriginalFileName metadata.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-15
Updated
2026-07-30

What it detects

This rule flags process creation events where LiveKD executables (livekd.exe or livekd64.exe) are launched, using either the image path ending or the OriginalFileName metadata. LiveKD can be used for live troubleshooting and, when abused, may support memory acquisition or dumping activities. The detection relies on Windows process creation telemetry and matches on executable name/path and PE metadata fields.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.