---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Playbook for T1003 - Defense Evasion - Mimikatz DCShadow

# Playbook for T1003 - Defense Evasion - Mimikatz DCShadow {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

This playbook provides systematic remediation steps to investigate incidents suspected to be caused by Mimikatz DCShadow. DCShadow is a feature in Mimikatz that simulates the behavior of a Domain Controller (a server controlling
Active Directory) to inject its own data, bypassing most of the standard security controls (including SIEMs).

Mimikatz DCShadow helps the attacker establish a rogue Domain Controller (DC) that becomes part of the Active Directory (AD). Once registered, it can act as a legitimate DC and cause damage.
* **[Set up the T1003 - Defense Evasion - Mimikatz DCShadow playbook](https://www.servicenow.com/docs/Lvw8os0k4KeKfAQ7yQ4K5A)**   
  Use the following steps to set up the T1003 - Defense Evasion - Mimikatz DCShadow playbook.
* **[Use the T1003 - Defense Evasion - Mimikatz DCShadow playbook](https://www.servicenow.com/docs/z9pFzoEdyjrSK0d7sVii9A)**   
  Use this playbook to investigate security incidents suspected to be caused by Mimikatz DCShadow. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the T1003 - Defense Evasion - Mimikatz DCShadow playbook.

