LSASS Memory Access by Non-System Process (Credential Access)

Detects cross-process memory access attempts targeting the Local Security Authority Subsystem Service (lsass.exe). The rule filters out known Microsoft-signed system processes and common Windows binaries to identify potential unauthorized credential dumping activity.