Mimikatz Credential Harvesting via LSASS Access
This rule detects potential credential dumping activities by monitoring for the execution of Mimikatz or command-line arguments associated with credential extraction (e.g., 'sekurlsa::logonpasswords'). Additionally, it monitors for suspicious process access attempts to 'lsass.exe' with specific high-privileged access masks often used by credential dumping tools to read process memory.
Microsoft Sentinel (KQL)

