Ransomware Series: LSASS Memory Access for Credential Dumping

This rule detects various methods used by adversaries to perform credential dumping from the Local Security Authority Subsystem Service (LSASS) process. It monitors for direct process access with suspicious handle permissions, the use of comsvcs.dll via rundll32.exe for MiniDump creation, the execution of memory dumping tools like procdump, and the creation of LSASS memory dump files by Task Manager.