image.png

Upon initial logon, LSASS will:

Dumping LSASS process memory

image.png

Rundll32.exe & Comsvcs.dll method

Can be done in CLI.

Flagged by AVs.

Run tasklist /svc to find lsass.exe and its process ID

Or

Get-Process lsass