Potential LSASS Process Dump Via Procdump (5afee48e-67dd-4e03-a783-f74259dcf998)
Detects suspicious uses of the SysInternals Procdump utility by using a special command line parameter in combination with the lsass.exe process. This way we are also able to catch cases in which the attacker has renamed the procdump executable.