LSASS Memory Dumping - Active Directory Credential Theft

This rule detects common methods used by adversaries to perform credential dumping by accessing the memory of the Local Security Authority Subsystem Service (LSASS). It specifically flags the use of Procdump to create a memory dump of LSASS, the use of the native Windows utility comsvcs.dll via rundll32 to dump process memory, and the creation of LSASS dump files via the Windows Task Manager.