Use the T1003 - Credential Dumping - Mimikatz DCsync playbook
Rversion finale: Australia
Mis à jour 12 mars 2026
1 minute de lecture
Use this playbook to investigate incidents suspected to be caused by Mimikatz DCSync. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the T1003 - Credential Dumping -
Mimikatz DCsync playbook.
Avant de commencer
Role required:
sn_si.admin
flow_designer
Procédure
When the playbook is triggered and starts executing, in Action 1, check the host activity on Splunk and look for any suspicious activities.
In Action 2, identify the owner of the server/endpoint/VM.
If the user is online, run the CrowdStrike EDR to gather a better scope of the system's activities.
In Action 3, gather information on the user's other account activities.
In Action 4, based on the investigation, verify if the server/endpoint/VM was ever used for credential dumping.
In Action 5, if the server/endpoint/VM wasn’t used for credential dumping, perform the following actions: