AdaptixC2 Creds-BOF LSASS/SAM/LSA credential dumping activity
Detects credential-dumping modules (such as nanodump, hashdump, and lsadump variants) associated with AdaptixC2 framework being invoked or used by the 'mscopilot.exe' process. The rule monitors for command-line arguments indicating credential extraction, unauthorized attempts to open handle to lsass.exe, and access to sensitive registry hives (SAM, Security, LSA) by the suspect process.
Microsoft Sentinel (KQL)

