Potential Credential Dumping Via WER - Application (a18e0862-127b-43ca-be12-1a542c75c7c5)
Detects Windows error reporting event where the process that crashed is lsass. This could be the cause of an intentional crash by techniques such as Lsass-Shtinkering to dump credential