Free kit

Free AI Tabletop Exercise Kit for SMBs

Sign up for the Cyber Defense & AI Brief and get it free.

Get the free kit

UC-L3-009

Mimikatz Command Line Detection

Windows Security / Sysmon Event ID 1

Use case development / Detect Unauthorized Access / Detect Credential Theft

sigma

Detection rule

title: Mimikatz Command Line Arguments
status: experimental
description: Detects common Mimikatz command line patterns
logsource:
  product: windows
  category: process_creation
detection:
  selection:
    CommandLine|contains:
      - 'sekurlsa'
      - 'kerberos::list'
      - 'privilege::debug'
      - 'token::elevate'
  condition: selection
falsepositives:
  - Legitimate penetration testing
level: critical
tags:
  - attack.credential_access
  - attack.t1003

Test cases

  • Execute Mimikatz with known arguments

False positive guidance

Coordinate with security testing teams for scheduling.

ATT&CK

Detection course