Mimikatz-like Activity Detection

This rule detects the execution of processes with command-line arguments indicative of Mimikatz usage. It specifically looks for the strings 'mimikatz', 'sekurlsa', or 'privilege::debug' in the command line of newly created processes (EventID 4688). This activity is commonly associated with credential dumping.