PowerShell Get-Process LSASS — Detection Rule

Detects a "Get-Process" cmdlet and it's aliases on lsass process, which is in almost all cases a sign of malicious activity

Read the full analysis on IntelFusions