SeDebugPrivilege Abuse - Token Privilege Enablement and LSASS Targeting
This rule detects potential credential dumping attempts against the Local Security Authority Subsystem Service (LSASS). It monitors two distinct suspicious behaviors: 1) The enablement of 'SeDebugPrivilege' by non-system processes via Windows security event 4703, and 2) Suspicious OpenProcess calls targeting sensitive Windows processes (lsass.exe, csrss.exe, winlogon.exe, services.exe, smss.exe) initiated by non-system accounts with high-level access rights.
Microsoft Sentinel (KQL)

