LSASS Memory Access Followed by Dump File With Non-.dmp Extension
Detects a process obtaining handle access to the LSASS process (Sysmon Event ID 10) followed by the creation of a file (Sysmon Event ID 11) using an extension other than '.dmp'. This behavior is characteristic of adversaries attempting to obfuscate credential dumping activities by bypassing simple extension-based detection rules.
Sigma

