LSASS Memory Access for Credential Dumping (T1003.001)

Detects techniques associated with LSASS process credential dumping, including direct handle access to the LSASS process with specific access masks (common in tools like Mimikatz), the use of rundll32.exe to invoke comsvcs.dll for memory dumping, and the creation of LSASS dump files on disk.