Pass-the-Hash / Credential Injection via mimikatz sekurlsa::pth (T1550.002)
The rule detects potential credential dumping activities by monitoring for the execution of Mimikatz or the use of its specific command-line arguments (e.g., sekurlsa::logonpasswords, /ntlm:). It also monitors for suspicious, unauthorized processes attempting to open a handle to the LSASS process to access its memory, a common technique for dumping credentials.
SentinelOne

