Create Remote Thread Into LSASS
Detect remote thread creation into LSASS consistent with credential dumping.
This content is not mapped to any local saved search. Add mapping
Create Remote Thread Into LSASS Help
This search needs Sysmon Logs with a Sysmon configuration, which includes EventCode 8 with lsass.exe. This search uses an input macro named
Open in Search