Hacktool - Credential Dumper Katz Variants Execution

Rule Info

Name
Hacktool - Credential Dumper Katz Variants Execution
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects execution of potentially credential dumping hack tools with naming patterns similar to mimikatz.exe. It's a common practice among offensive tools developers to use "katz" string at the tool name, hinting the tool as a credential dumping tool.
Reference
Internal Research
Date
2025-04-21 00:00:00
Modified
None
Id
ffa61b72-dbb6-41ec-92ee-b143b5e418a6
Tags
attack.credential-access attack.t1003
Type
Nextron Sigma feed only (private)

Rule History