Windows process: lsass.exe
lsass.exe
Handles authentication (e.g., NTLM, Kerberos).
Stores password hashes in memory temporarily.
Target for credential dumping tools like Mimikatz.
which is responsible for create hash (NTLM Hash)