With a # of signed process dump utilities out there, would MSFT dev shops consider building in logic to prohibit LSASS dumping in such tools?
Sure, it does not solve the problem class, but it does introduce a layer of deterrence for the lolbin attack aspect.
Maybe...