LSASS Process Dump Artefact In CrashDumps Folder (6902955a-01b7-432c-b32a-6f5f81d8f625)
Detects the presence of an LSASS dump file in the "CrashDumps" folder. This could be a sign of LSASS credential dumping. Techniques such as the LSASS Shtinkering have been seen abusing the Windows Error Reporting to dump said process.