select mitre ttp · structured artifact checklist · spl and kql blocks · markdown playbook export · runs locally
tactic filter
search technique id or name
87 matching ttp(s)
Process
Event Log
Registry
File
Network
No LSASS access may mean dump used kernel driver or offline image analysis only.
splunk spl
index=windows EventCode=10 TargetImage="*lsass.exe"