Hello RSA community, We are looking for a way to better key in on LSASS Hash harvesting in packet capture. Currently we are keying off of the event directory being system32\ however we are looking for other relevant meta for a custom ESA alert. I would like to use action is equal to "kerberos ap request" but there are a large amount of false positives with that logic. If anyone has any recommendations on how to better alert on this activity in packet traffic I would be very interested. RSA Live seems to have some oob rules for this activity but they all look to be for endpoint and log not packet traffic. Thanks for the feedback.