Mimikatz Use

 Original Source: [Sigma source]
Title: Mimikatz Use
Status: test
Description:This method detects mimikatz keywords in different Eventlogs (some of them only appear in older Mimikatz version that are however still used by different threat groups)
References:
  -https://tools.thehacker.recipes/mimikatz/modules
Author: Florian Roth (Nextron Systems), David ANDRE (additional keywords)
Date: 2017-01-10
modified:2022-01-05
Tags:
  • -'attack.s0002'
  • -'attack.lateral-movement'
  • -'attack.credential-access'
  • -'car.2013-07-001'
  • -'car.2019-04-004'
  • -'attack.t1003.002'
  • -'attack.t1003.004'
  • -'attack.t1003.001'
  • -'attack.t1003.006'
Logsource:
  • product: windows
Detection:
  keywords:
    - 'dpapi::masterkey'
    - 'eo.oe.kiwi'
    - 'event::clear'
    - 'event::drop'
    - 'gentilkiwi.com'
    - 'kerberos::golden'
    - 'kerberos::ptc'
    - 'kerberos::ptt'
    - 'kerberos::tgt'
    - 'Kiwi Legit Printer'
    - 'lsadump::'
    - 'mimidrv.sys'
    - '\mimilib.dll'
    - 'misc::printnightmare'
    - 'misc::shadowcopies'
    - 'misc::skeleton'
    - 'privilege::backup'
    - 'privilege::debug'
    - 'privilege::driver'
    - 'sekurlsa::'
  filter:
    EventID: '15'
  condition:keywords and not filter
Falsepositives:
  -Naughty administrators
  -AV Signature updates
  -Files with Mimikatz in their filename
Level: high