LSASS handle leak via Seclogon

Identifies suspicious access to LSASS process from a callstack pointing to seclogon.dll that may indicate an attempt to leak an LSASS handle via abusing the Secondary Logon service in preparation for credential access.

Back to all rules