Product
This detection logic identifies credential dumping attempts by monitoring for unauthorized processes requesting PROCESS_VM_READ access to the lsass.exe process memory using Sysmon EventID 10.