Playbook for T1003 - Credential Dumping - Mimikatz DCSync

  • 릴리스 버전: Australia
  • 업데이트 날짜 2026년 03월 12일
  • 소요 시간: 1분
  • This playbook provides systematic remediation steps to investigate incidents suspected to be caused by Mimikatz DCSync. This playbook triggers when one of the Mimikatz functions (lsadump::dcsync) is used. The function is typically used on attacked Domain Controllers (DC).

    Mimikatz is a popular hacking tool that enables users to issue commands that help retrieve confidential data from the attacked system. The confidential data includes passwords, their hashes, and others.

    주:
    This is a high-fidelity alert, which is assumed to be rarely triggered. When it triggers, you should notify a senior team member or Manager immediately.