{ "name": "Malicious Process Execution - Mimikatz", "incident_id": "5001", "creation_time": 1705312200000, "modification_time": 1705312200000, "status": "new", "severity": "high", "alert_count": 1, "assigned_user_mail": "", "description": "Mimikatz credential dumping tool execution detected on WORKSTATION-042 under user context DOMAIN\\jsmith", "alert_sources": [ "XDR Agent" ] }