Password Dumper Activity on LSASS (aa1697b7-d611-4f9a-9cb2-5125b4ccfd5c)
Detects process handle on LSASS process with certain access mask and object type SAM_DOMAIN
Detects process handle on LSASS process with certain access mask and object type SAM_DOMAIN