LSA PPL Protection Setting Modification via CommandLine — Detection Rule
Detects modification of LSA PPL protection settings via CommandLine. It may indicate an attempt to disable protection and enable credential dumping tools to access LSASS process memory.