Use the T1003 - Credential Dumping - Mimikatz DCsync playbook
リリースバージョン: Australia
更新日 2026年03月12日
所要時間:3分
Use this playbook to investigate incidents suspected to be caused by Mimikatz DCSync. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the T1003 - Credential Dumping -
Mimikatz DCsync playbook.
始める前に
Role required:
sn_si.admin
flow_designer
手順
When the playbook is triggered and starts executing, in Action 1, check the host activity on Splunk and look for any suspicious activities.
In Action 2, identify the owner of the server/endpoint/VM.
If the user is online, run the CrowdStrike EDR to gather a better scope of the system's activities.
In Action 3, gather information on the user's other account activities.
In Action 4, based on the investigation, verify if the server/endpoint/VM was ever used for credential dumping.
In Action 5, if the server/endpoint/VM wasn’t used for credential dumping, perform the following actions: