Use the T1003 - Credential Dumping - Mimikatz DCsync playbook
Release version: Xanadu
Updated August 1, 2024
1 minute to read
Use this playbook to investigate incidents suspected to be caused by Mimikatz DCSync. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the T1003 - Credential Dumping -
Mimikatz DCsync playbook.
Before you begin
Role required:
sn_si.admin
flow_designer
Procedure
When the playbook is triggered and starts executing, in Action 1, check the host activity on Splunk and look for any suspicious activities.
In Action 2, identify the owner of the server/endpoint/VM.
If the user is online, run the CrowdStrike EDR to gather a better scope of the system's activities.
In Action 3, gather information on the user's other account activities.
In Action 4, based on the investigation, verify if the server/endpoint/VM was ever used for credential dumping.
In Action 5, if the server/endpoint/VM wasn’t used for credential dumping, perform the following actions: