detecting-mimikatz-execution-patterns
Identifies potential Mimikatz execution patterns for proactive cybersecurity threat hunting.
Install
mkdir -p .claude/skills/detecting-mimikatz-execution-patterns && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/16320" && unzip -o skill.zip -d .claude/skills/detecting-mimikatz-execution-patterns && rm skill.zipInstalls to .claude/skills/detecting-mimikatz-execution-patterns
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Detect Mimikatz execution through command-line patterns, LSASS access signatures, binary indicators, and in-memoryKey capabilities
- →Proactively hunt for Mimikatz execution indicators
- →Analyze EDR telemetry for suspicious patterns
- →Query SIEM for relevant log data
- →Correlate findings across multiple data sources
- →Map detection findings to MITRE ATT&CK techniques
How it works
The skill outlines a workflow for detecting Mimikatz execution patterns by formulating hypotheses, identifying data sources, executing queries against EDR/SIEM platforms, analyzing results, and correlating activity to threat actor TTPs.
Inputs & outputs
When to use detecting-mimikatz-execution-patterns
- →Hunting for credential dumping threats
- →Analyzing EDR telemetry
- →Performing security assessments
About this skill
Detecting Mimikatz Execution Patterns
When to Use
- When proactively hunting for indicators of detecting mimikatz execution patterns in the environment
- After threat intelligence indicates active campaigns using these techniques
- During incident response to scope compromise related to these techniques
- When EDR or SIEM alerts trigger on related indicators
- During periodic security assessments and purple team exercises
Prerequisites
- EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
- SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
- Sysmon deployed with comprehensive configuration
- Windows Security Event Log forwarding enabled
- Threat intelligence feeds for IOC correlation
Workflow
- Formulate Hypothesis: Define a testable hypothesis based on threat intelligence or ATT&CK gap analysis.
- Identify Data Sources: Determine which logs and telemetry are needed to validate or refute the hypothesis.
- Execute Queries: Run detection queries against SIEM and EDR platforms to collect relevant events.
- Analyze Results: Examine query results for anomalies, correlating across multiple data sources.
- Validate Findings: Distinguish true positives from false positives through contextual analysis.
- Correlate Activity: Link findings to broader attack chains and threat actor TTPs.
- Document and Report: Record findings, update detection rules, and recommend response actions.
Key Concepts
| Concept | Description |
|---|---|
| T1003.001 | LSASS Memory |
| T1003.006 | DCSync |
| T1558.003 | Kerberoasting |
| T1558.001 | Golden Ticket |
Tools & Systems
| Tool | Purpose |
|---|---|
| CrowdStrike Falcon | EDR telemetry and threat detection |
| Microsoft Defender for Endpoint | Advanced hunting with KQL |
| Splunk Enterprise | SIEM log analysis with SPL queries |
| Elastic Security | Detection rules and investigation timeline |
| Sysmon | Detailed Windows event monitoring |
| Velociraptor | Endpoint artifact collection and hunting |
| Sigma Rules | Cross-platform detection rule format |
Common Scenarios
- Scenario 1: Standard sekurlsa::logonpasswords credential dump
- Scenario 2: PowerShell Invoke-Mimikatz reflective loading
- Scenario 3: DCSync from non-DC host
- Scenario 4: Golden ticket creation for persistence
Output Format
Hunt ID: TH-DETECT-[DATE]-[SEQ]
Technique: T1003.001
Host: [Hostname]
User: [Account context]
Evidence: [Log entries, process trees, network data]
Risk Level: [Critical/High/Medium/Low]
Confidence: [High/Medium/Low]
Recommended Action: [Containment, investigation, monitoring]
When not to use it
- →When EDR platform is not available
- →When SIEM with relevant log data is not ingested
- →When Sysmon is not deployed with complete configuration
Prerequisites
Limitations
- →Requires an EDR platform with process and network telemetry.
- →Requires a SIEM with relevant log data ingested.
- →Requires Sysmon deployed with complete configuration.
How it compares
This skill provides a structured, proactive threat hunting workflow for Mimikatz detection, integrating EDR, SIEM, and MITRE ATT&CK, which is more complete than relying solely on automated alerts.
Compared to similar skills
detecting-mimikatz-execution-patterns side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| detecting-mimikatz-execution-patterns (this skill) | 0 | 2mo | No flags | Advanced |
| protocol-reverse-engineering | 9 | 7mo | Review | Advanced |
| equilateral-agents | 5 | 9mo | No flags | Intermediate |
| secops-triage | 4 | 7mo | No flags | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by aibot88
View all by aibot88 →You might also like
protocol-reverse-engineering
wshobson
Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. Use when analyzing network traffic, understanding proprietary protocols, or debugging network communication.
equilateral-agents
Equilateral-AI
22 production-ready AI agents with database-driven orchestration for security reviews, code quality analysis, deployment validation, infrastructure checks, and compliance. Auto-activates for security concerns, deployment tasks, code reviews, quality checks, and compliance questions. Includes upgrade paths to enterprise features (GDPR, HIPAA, multi-account AWS, ML-based optimization).
secops-triage
Expert guidance for security alert triage. Use this when the user asks to "triage" an alert or case.
netflows
BrownFineSecurity
Network flow extractor that analyzes pcap/pcapng files to identify outbound connections with automatic DNS hostname resolution. Use when you need to enumerate network destinations, identify what hosts a device communicates with, or map IP addresses to hostnames from packet captures.
azure-bgp
benchflow-ai
Analyze and resolve BGP oscillation and BGP route leaks in Azure Virtual WAN–style hub-and-spoke topologies (and similar cloud-managed BGP environments). Detect preference cycles, identify valley-free violations, and propose allowed policy-level mitigations while rejecting prohibited fixes.
secops-investigate
Expert guidance for deep security investigations. Use this when the user asks to "investigate" a case, entity, or incident.