Language:
After a user logs on, attackers can attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
MITRE ATT&CK description
ADsecurity.org - Extract Hashes from LSASS
Microsoft - Using ProcDump
Name: OS Credential Dumping: LSASS Memory
Codename: I-ProcessInjectionLsass
Severity: Critical