LSASS Memory Access by Suspicious Process
Process "c:\users\temp\update.exe" attempted to open LSASS.exe memory with PROCESS_VM_READ and PROCESS_QUERY_INFORMATION access flags. This behavior is characteristic of credential dumping tools attempting to extract cached credentials from the Windows LSASS process. The accessing process has no legitimate reason to read LSASS memory and matches behavioral signatures of Mimikatz.

