Credential Dumping via LSASS Access
Detects potential credential dumping activities by monitoring process executions associated with known tools (Mimikatz, Procdump, Gsecdump) or commands that interact with the LSASS process memory to extract secrets.
Microsoft Sentinel (KQL)

