CPE
Detection of unauthorized handles to the Local Security Authority Subsystem Service (LSASS) process to identify potential credential dumping attempts on Windows systems.