Potential Credential Dumping Attempt Via PowerShell — Detection Rule
Detects a PowerShell process requesting access to "lsass.exe", which can be indicative of potential credential dumping attempts
Detects a PowerShell process requesting access to "lsass.exe", which can be indicative of potential credential dumping attempts