通过Sysmon的-l参数可以探测到DLL加载(ImageLoaded): REF:https://securityriskadvisors.com/blog/post/detecting-in-memory-mimikatz/ 相关文章: 2021-07-09 2021-04-05 2021-05-03 2021-12-19 2021-12-27 2021-04-08 2021-06-06