A cybersecurity analyst conducts proactive threat hunting on a network by correlating and searching the Sysmon and Windows event logs. The analyst used the following query as part of their hunt:
Query: "mimikatz" NOT "eventCode=4658" NOT "EventCode=4689" EventCode=10 | status count by _time, SourceImage, TargetImage, GrantedAccess
Based on the above, what potential indicator of compromise is the threat hunter looking for?