LSA PPL Protection Setting Modification via CommandLine — Detection Rule

Detects modification of LSA PPL protection settings via CommandLine. It may indicate an attempt to disable protection and enable credential dumping tools to access LSASS process memory.

Read the full analysis on IntelFusions