Potential Credential Dumping Activity Via LSASS (5ef9853e-4d0e-4a70-846f-a9ca37d876da)
Detects process access requests to the LSASS process with specific call trace calls and access masks. This behaviour is expressed by many credential dumping tools such as Mimikatz, NanoDump, Invoke-Mimikatz, Procdump and even the Taskmgr dumping feature.