Potential Credential Dumping Attempt Via PowerShell — Detection Rule

Detects a PowerShell process requesting access to "lsass.exe", which can be indicative of potential credential dumping attempts

Read the full analysis on IntelFusions