Memory dumping is a classic technique to recover some hidden information, including passwords and credentials. One of the Active Directory techniques is dumping LSASS memory using the Task Manager. Mimikatz has great capabilities, such as the features discussed before; one of them is dumping LSASS memory from the LSASS.dmp file, as shown:
If the operation succeeds, you will receive this message: