Potential PhantomCore or PhantomGraph Backdoor, LSASS Dumping, and Reverse SSH Activity
This query identifies creation/loading of SysExcSvc.dll and SysReadSvc.dll along with suspicious LSASS memory dumping, reverse SSH tunnel creation. These patterns are prevalent with "Phantom" including unusual OneDrive or Microsoft Graph access from LOLBins or unexpected processes.
Microsoft Sentinel (KQL)

