Akira - LSASS Memory Dump via Comsvcs MiniDump or Direct Handle
Detects unauthorized credential dumping attempts against the Local Security Authority Subsystem Service (LSASS) process. The rule identifies suspicious use of system utilities like 'comsvcs.dll' via rundll32, cross-process handle access by unauthorized processes, and the execution of offensive security tools such as lsassy and crackmapexec.
SentinelOne

