Credential Dumping Attempts via LSASS or NTDS.dit Access

This rule detects attempts to access the Local Security Authority Subsystem Service (LSASS) process memory or the NTDS.dit file, which are common targets for credential dumping. It specifically looks for Security Event ID 4656 (A handle to an object was requested) where the ObjectName is either 'lsass.exe' or 'ntds.dit' and the AccessMask indicates read or all access permissions. The rule then summarizes these events by user, computer, and IP address, flagging if two or more such events occur.