Suspicious Non-System Process Access to LSASS (T1003.001)
Detects unauthorized cross-process memory access attempts targeting the Local Security Authority Subsystem Service (lsass.exe). Such attempts are commonly associated with credential dumping techniques to extract credentials from memory.
SentinelOne

