Title:Suspicious Interactive PowerShell as SYSTEM Status:test Description:Detects the creation of files that indicator an interactive use of PowerShell in the SYSTEM user context References: -https://jpcertcc.github.io/ToolAnalysisResultSheet/details/PowerSploit_Invoke-Mimikatz.htm Author: Florian Roth (Nextron Systems) Date: 2021-12-07 modified:2022-08-13 Tags: