LSASS Memory Dump via Direct Process Access (T1003.001)
Detects unauthorized or suspicious processes attempting to access the memory of the Local Security Authority Subsystem Service (lsass.exe). This activity often indicates attempts to dump process memory to harvest sensitive credentials, a common technique used by attackers to facilitate lateral movement.
SentinelOne

