Set up the T1003 - Credential Dumping - Mimikatz DCsync playbook
Release version: Yokohama
Updated January 30, 2025
1 minute to read
Use the following steps to set up the T1003 - Credential Dumping - Mimikatz DCsync playbook.
Before you begin
Role required:
sn_si.admin
flow_designer
Make sure you have installed Security Operations Spoke (sn_sec_spoke).
Procedure
Login as a user with sn_si.user and flow_designer roles.
Navigate to All > Flow Designer and select the T1003 - Credential Dumping - Mimikatz DCsync playbook.
Optional: Create a copy of the T1003 - Credential Dumping - Mimikatz DCsync playbook flow and make the necessary modifications.
To create a copy of the playbook's flow, select the icon and select Copy flow. Perform this step only if you plan to customize or make specific changes to the flow.