Remote-Origin LSASS Memory Access for Credential Dumping
Detects unauthorized processes requesting memory access to lsass.exe with read permissions commonly associated with credential dumping techniques like Mimikatz. It identifies remote handle requests to lsass.exe, which are frequently used by tools deployed via network services or remote execution methods to extract credentials from memory.
Sigma

