Suspicious LSASS Access (Credential Dumping Precursor to Ransomware Deployment)

This rule detects potentially unauthorized access or memory dumping attempts against the Local Security Authority Subsystem Service (LSASS) process. It monitors for events where processes interact with LSASS or execute commands containing 'lsass.exe', 'MiniDump', or 'comsvcs.dll', while excluding known administrative and benign processes like Task Manager, Procdump, and Windows Error Reporting.