HackTool - Mimikatz Execution


Description

Detection well-known mimikatz command line arguments

Query · sigma

selection_tools_name:
  CommandLine|contains:
  - DumpCreds
  - mimikatz
selection_function_names:
  CommandLine|contains:
  - ::aadcookie
  - ::detours
  - ::memssp
  - ::mflt
  - ::ncroutemon
  - ::ngcsign
  - ::printnightmare
  - ::skeleton
  - ::preshutdown
  - ::mstsc
  - ::multirdp
selection_module_names:
  CommandLine|contains:
  - 'rpc::'
  - 'token::'
  - 'crypto::'
  - 'dpapi::'
  - 'sekurlsa::'
  - 'kerberos::'
  - 'lsadump::'
  - 'privilege::'
  - 'process::'
  - 'vault::'
condition: 1 of selection_*

Known false positives

  • Unlikely
Raw source HackTool - Mimikatz Execution · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: HackTool - Mimikatz Execution
id: a642964e-bead-4bed-8910-1bb4d63e3b4d
status: test
description: Detection well-known mimikatz command line arguments
references:
    - https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment
    - https://tools.thehacker.recipes/mimikatz/modules
author: Teymur Kheirkhabarov, oscd.community, David ANDRE (additional keywords), Tim Shelton
date: 2019-10-22
modified: 2023-02-21
tags:
    - attack.credential-access
    - attack.t1003.001
    - attack.t1003.002
    - attack.t1003.004
    - attack.t1003.005
    - attack.t1003.006
logsource:
    category: process_creation
    product: windows
detection:
    selection_tools_name:
        CommandLine|contains:
            - 'DumpCreds'
            - 'mimikatz'
    selection_function_names: # To cover functions from modules that are not in module_names
        CommandLine|contains:
            - '::aadcookie' # misc module
            - '::detours' # misc module
            - '::memssp' # misc module
            - '::mflt' # misc module
            - '::ncroutemon' # misc module
            - '::ngcsign' # misc module
            - '::printnightmare' # misc module
            - '::skeleton' # misc module
            - '::preshutdown'  # service module
            - '::mstsc'  # ts module
            - '::multirdp'  # ts module
    selection_module_names:
        CommandLine|contains:
            - 'rpc::'
            - 'token::'
            - 'crypto::'
            - 'dpapi::'
            - 'sekurlsa::'
            - 'kerberos::'
            - 'lsadump::'
            - 'privilege::'
            - 'process::'
            - 'vault::'
    condition: 1 of selection_*
falsepositives:
    - Unlikely
level: high

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.