LSASS Memory Access for Credential Dumping (T1003.001)

Detects unauthorized processes attempting to open handles to the Local Security Authority Subsystem Service (lsass.exe) with sensitive access rights (e.g., PROCESS_VM_READ, PROCESS_QUERY_INFORMATION). These access patterns are frequently utilized by credential dumping tools like Mimikatz, ProcDump, or malicious abuse of system utilities to extract plaintext passwords or NTLM hashes from memory.