Playbook for T1003 - Credential Dumping - Mimikatz DCSync

  • リリースバージョン: Australia
  • 更新日 2026年03月12日
  • 所要時間:1分
  • This playbook provides systematic remediation steps to investigate incidents suspected to be caused by Mimikatz DCSync. This playbook triggers when one of the Mimikatz functions (lsadump::dcsync) is used. The function is typically used on attacked Domain Controllers (DC).

    Mimikatz is a popular hacking tool that enables users to issue commands that help retrieve confidential data from the attacked system. The confidential data includes passwords, their hashes, and others.

    注:
    This is a high-fidelity alert, which is assumed to be rarely triggered. When it triggers, you should notify a senior team member or Manager immediately.