OnyxC2 LSASS memory dumping via PROCESS_VM_READ and MiniDumpWriteDump from unsigned process

Detects LSASS memory access via PROCESS_VM_READ combined with MiniDumpWriteDump-style API usage from an unsigned or untrusted process, correlated with a nearby dump-file creation, consistent with OnyxC2's premium-tier credential dumping.

Microsoft Sentinel (KQL)