Direct Syscall LSASS Memory Dump via Sysmon Event ID 10 Unsigned CallTrace
Detects suspicious access to the Local Security Authority Subsystem Service (lsass.exe) process memory, indicated by Sysmon Event ID 10 with an 'UNKNOWN' call trace. This pattern is characteristic of direct syscall usage or memory injection techniques used to bypass standard Windows API hooking and security monitoring, common in credential dumping attempts.
Microsoft Sentinel (KQL)

