We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
HackTool:PowerShell/Mimikatz.E
Detected by Microsoft Defender Antivirus
Aliases: No associated aliases
Summary
HackTool:PowerShell/Mimikatz.E is the detection for various PowerShell-based Mimikatz, some of which can be seen in frameworks such as PowerSploit and Empire.
Learn more about the role HackTool:PowerShell/Mimikatz.E plays in Actor profile: Storm-1147 deploys ransomware after Gootloader hand-offs.
Remove the infected device from the network.
Thoroughly investigate for other signs of infection in the network.
Update the password for any affected user.