Mimikatz and unsigned-process LSASS access with suspicious rights
Detects LSASS memory access with credential-dumping-consistent access rights from unsigned or non-allowlisted processes, indicative of Mimikatz-driven credential theft used by Gunra ransomware affiliates.
Microsoft Sentinel (KQL)

