Mimikatz sekurlsa::logonpasswords LSASS Credential Dump

Detects credential dumping attempts against the Local Security Authority Subsystem Service (LSASS) process. The rule identifies processes attempting to access LSASS memory using specific access masks often associated with credential extraction, or the presence of the Mimikatz 'sekurlsa::logonpasswords' command in the process command line.