Mimikatz Credential Theft via Known Command Keywords (T1003)
Detects the execution of processes containing command-line arguments associated with the Mimikatz post-exploitation tool, such as credential dumping, privilege escalation, and certificate manipulation keywords.
SentinelOne

