Windows Event Logs: Mimikatz Keyword Indicators

Detects Mimikatz-related keywords in Windows event logs while filtering Sysmon EventID 15 to limit noise.

FreeReviewedSigma · High · v2
Product
windows
Author
Florian Roth (Nextron Systems), David ANDRE (additional keywords) (SigmaHQ), DRL 1.1
Published
2017-01-10
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule looks for common Mimikatz-related command and module keywords in Windows event logs. Such strings often appear when an attacker executes credential access, lateral movement, or ticket manipulation activities using Mimikatz tooling. Detection relies on event log telemetry that preserves the relevant keyword text and filters out matches tied to Sysmon EventID 15 to reduce noise.

Related detections9 linkedT1003.002 — drag to rearrange
Windows Process Creation: Detect Mimikatz Tool and Module Command-Line Usage
Windows System Service Execution of Credential Dumping Tools (Service Control Manager Event 7045)
Windows Security EID 4697 Service Execution of Credential Dumping Tools
Windows PUA: MemProcFS memory dump mounting via -device
Windows Credential Dump Tool Artifacts Written to Disk via File Events
Windows Named Pipe Creation for Known Credential Dumping Tool Pipe Names
Malicious Mimikatz Credential Access Module Invocation
Zeek SMB: Network Share File Transfers of Credential-Related Filenames
Zeek SMB Files: Impacket SecretDump Access to ADMIN$ and System32 .tmp Droppers
Windows Event Logs: Mimikatz Keyword Indicators
Pivot detection · T1003.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.