Feral Wolf LSASS dumping via DumpIt/MemProcFS/Dokan
This rule detects the use of specific tools associated with credential dumping and memory forensics, including Dokan driver installations for file system mounting, the use of DumpIt for creating memory dumps, and the subsequent analysis of these dumps using MemProcFS to access sensitive process memory information such as LSASS minidumps.
Microsoft Sentinel (KQL)

