Potential Invoke-Mimikatz PowerShell Script

 Original Source: [Sigma source]
Title: Potential Invoke-Mimikatz PowerShell Script
Status: test
Description:Detects Invoke-Mimikatz PowerShell script and alike. Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords.
References:
  -https://www.elastic.co/guide/en/security/current/potential-invoke-mimikatz-powershell-script.html#potential-invoke-mimikatz-powershell-script
Author: Tim Rauch, Elastic (idea)
Date: 2022-09-28
modified:None
Tags:
  • -'attack.credential-access'
  • -'attack.t1003'
Logsource:
  • category: ps_script
  • product: windows
Detection:
  selection_1:
    ScriptBlockText|contains|all:
      -'DumpCreds'
      -'DumpCerts'

  selection_2:
    ScriptBlockText|contains: 'sekurlsa::logonpasswords'
  selection_3:
    ScriptBlockText|contains|all:
      -'crypto::certificates'
      -'CERT_SYSTEM_STORE_LOCAL_MACHINE'

  condition:1 of selection*
Falsepositives:
  -Mimikatz can be useful for testing the security of networks
Level: high