// REFERENCE

Sysmon 10 — Process access

Log: Sysmon/Operational High risk

A process opened a handle to another (Sysmon). The star case is access to LSASS with memory-read rights (0x1010/0x1410), the classic signature of credential dumping (Mimikatz and friends). Filter by TargetImage lsass.exe.

Related tools

Work with this in:

Related

Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.