blue-team-mimikatz-detection

🔐 Blue Team Project: Detecting Mimikatz with Splunk + Sysmon

🎯 What This Project Is About

I built this lab to simulate how a Blue Team can detect a credential dumping attack using Sysmon and Splunk.
I ran a real Mimikatz attack inside a Windows 10 VM and created a Splunk alert to catch it.


🛠 Tools & Setup


✅ What I Did

1. Set up Windows 10 VM

I created a clean Windows 10 VM on VirtualBox.
Windows VM
(Optional initial setup screenshot)
Windows Setup


2. Installed Sysmon and Verified Logs


3. Installed Splunk and Ingested Sysmon Logs


4. Simulated the Attack with Mimikatz


5. Detected & Alerted in Splunk

Alert Configuration
Alert Config

Alert Triggered in Splunk
Alert Triggered


🔍 What I Learned


🚀 Next