LSASS Memory Access by Non-Standard or Unsigned Process (T1003.001)

Detects cross-process access to the Local Security Authority Subsystem Service (LSASS) memory by processes that are not standard Microsoft-signed system components. This behavior is often indicative of credential dumping activity using tools like Mimikatz or other custom malicious utilities attempting to read sensitive memory contents.