LSASS dumped via WerFaultSecure.exe: WSASS launches WerFaultSecure with undocumented args creating proc.png/proce.png minidumps; requires Local Admin. Detect via Sysmon Event ID 1 commandline and SIGMA rule for WerFaultSecure outside System32. #LSASS #Sysmon #T1003.001 https://bit.ly/4r8xxbU