Suspicious LSASS Memory Access - Potential Credential Dumping
This rule detects cross-process memory access attempts against the Local Security Authority Subsystem Service (LSASS). Accessing LSASS memory is a common technique used by attackers to dump credentials (e.g., cleartext passwords, NTLM hashes, Kerberos tickets) for lateral movement and privilege escalation. The rule filters out known legitimate processes and system-signed components to reduce false positives.
SentinelOne

