MemProcFS mounting memory dump and accessing lsass minidump
Detects evidence of potential credential dumping from the Local Security Authority Subsystem Service (LSASS) process. The rule monitors for two distinct behaviors: the use of MemProcFS with device memory access flags targeting a RAW file, and the creation of files containing 'lsass.exe', 'minidump', and 'readme.txt' in their paths or filenames, which is characteristic of certain post-exploitation toolkits that harvest LSASS memory.
Microsoft Sentinel (KQL)

