Most Popular Detection 2026: LSASS Memory Dump via comsvcs.dll MiniDump Export (rundll32)
Detects the use of rundll32.exe to invoke the MiniDump function of comsvcs.dll targeting the lsass.exe process. This technique is a well-known living-off-the-land (LotL) method used by adversaries to create a memory dump of LSASS, which can then be exfiltrated and analyzed offline using tools like Mimikatz to extract credentials.
Microsoft Sentinel (KQL)

