LoFP LoFP / t1550.003

t1550.003

TitleTags
although highly unlikely, legitimate applications may use the same command line parameters as mimikatz.
although unlikely, legitimate applications may use the same command line parameters as rubeus. filter as needed.
legitimate applications may obtain a handle for winlogon.exe. filter as needed
unlikely
web browsers and third party application might generate similar activity. an initial baseline is required.