CW Security PSA Oct 31 2020 - Cobalt Strike and Mimikatz

So we're seeing this PSA from ConnectWise @ https://www.connectwise.com/company/trust, and we appreciate the information and guidelines but they left part of it a bit vague:

"Check for the presence of the tools Cobalt Strike and Mimikatz."

Great idea!

But... how? I mean, I can look for 'mimikatz.exe' or something, but that seems a bit brute-force and prone to foiling through obfuscation, and my initial bit of research on Cobalt Strike suggests that I'm more likely to find it by looking for open ports than by any particular EXE. Does anyone who's more into this side of things have better suggestions before I start cobbling together some monitoring & scripting?

