Credential Dumping Attempt Via WerFault (e5b33f7d-eb93-48b6-9851-09e1e610b6d7)
Detects process LSASS memory dump using Mimikatz, NanoDump, Invoke-Mimikatz, Procdump or Taskmgr based on the CallTrace pointing to ntdll.dll, dbghelp.dll or dbgcore.dll for win10, server2016 and up.