Rundll32 comsvcs.dll LSASS Dump via lsassy (Bumblebee/Akira)
Detects the use of rundll32.exe to invoke the MiniDump export function of comsvcs.dll to create a memory dump of the LSASS process. This technique is often associated with post-exploitation credential access tools like lsassy or manual execution via remote management tools (e.g., WMI, MMC) by threat actors such as those in the Bumblebee/Akira ransomware intrusion chain.
Sigma

