Most Popular Detection 2026: LSASS Memory Access for Credential Dumping

Detects unauthorized processes attempting to open handles to the Local Security Authority Subsystem Service (LSASS) process with access rights consistent with credential dumping (e.g., PROCESS_VM_READ, PROCESS_ALL_ACCESS). This rule also specifically flags the use of well-known tools and techniques such as Mimikatz, ProcDump, and the abuse of rundll32.exe with comsvcs.dll for memory extraction, which is indicative of OS Credential Dumping (T1003.001).