Password Dumper Remote Thread in LSASS (f239b326-2f41-4d6b-9dfa-c846a60ef505)
Detects password dumper activity by monitoring remote thread creation EventID 8 in combination with the lsass.exe process as TargetImage. The process in field Process is the malicious program. A single execution can lead to hundreds of events.