Remote LSASS Process Access Through Windows Remote Management — Detection Rule

Detects remote access to the LSASS process via WinRM. This could be a sign of credential dumping from tools like mimikatz.

Read the full analysis on IntelFusions