Detection: selection: TargetFilename|startswith:
'C:\Windows\System32\config\systemprofile\AppData\Local\CrashDumps\' TargetFilename|contains:
'lsass.exe.' TargetFilename|endswith:
'.dmp' condition:selection Falsepositives:
-Rare legitimate dump of the process by the operating system due to a crash of lsass Level:high