Evading WinDefender ATP credential-theft: a hit after a hit-and-miss start.
tl;dr PssCaptureSnapshot syscall clones the process then you don't need to do ReadProcessMemory against the original process and avoid LSASS read detection.
https://www.matteomalvica.com/blog/2019/12/02/win-defender-atp-cred-bypass/