LSA Secrets or SAM Database Dump Attempt via Registry Key Access (4656)
Detects attempts by non-system user accounts to access the SAM or SECURITY registry hives. These hives contain sensitive credential material, and unauthorized access is a common indicator of credential dumping activities, often associated with tools like Mimikatz or scripts attempting to extract local account hashes.
Microsoft Sentinel (KQL)

