Remcos RAT Loader Attempting LSA Secret Access

Detects attempts by processes identified as Remcos RAT or its loader (GST*.com) to access Local Security Authority (LSA) secrets. This activity is indicative of credential dumping, where an attacker tries to extract sensitive authentication material from the system.