LSA boot-key subkey access (JD/Skew1/GBG/Data) ahead of SAM dump
Detects anomalous access to specific registry keys under SYSTEM\CurrentControlSet\Control\Lsa that are associated with LSA secrets. The rule monitors for multiple registry operations (set, create, delete) performed by processes other than standard Windows system processes (lsass.exe, svchost.exe, winlogon.exe, services.exe), which is often indicative of credential dumping attempts.
Microsoft Sentinel (KQL)

