Mimikatz-like Activity Detection
This rule detects the execution of processes with command-line arguments indicative of Mimikatz usage. It specifically looks for the strings 'mimikatz', 'sekurlsa', or 'privilege::debug' in the command line of newly created processes (EventID 4688). This activity is commonly associated with credential dumping.
Microsoft Sentinel (KQL)

