Use the T1003 - Defense Evasion - Mimikatz DCShadow playbook
Freigeben Version: Australia
Aktualisiert 12. März 2026
1 Minute Lesedauer
Use this playbook to investigate security incidents suspected to be caused by Mimikatz DCShadow. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the T1003 - Defense Evasion
- Mimikatz DCShadow playbook.
Vorbereitungen
Role required:
sn_si.admin
flow_designer
Prozedur
When the playbook is triggered and starts executing, in Action 1, find out which account is responsible for the creation of the new DC (Domain Controller).
In Action 2, reach out to the user to validate the business justification.
You can use the provided email template to contact the user.
In Action 3, check whether the user provided a valid business justification.
In Action 4, if the user provided a valid business justification, perform the following steps:
In Action 7, after the post incident review, the flow ends.
In Action 8, if the user didn’t provide a valid business justification, perform the following steps:
Abbildung : 2. Using the T1003 - Defense Evasion - Mimikatz DCShadow playbook
In Action 9, lock down or quarantine all the accounts, computers, and other devices involved.
In Action 10, perform a forensic investigation on the locked-down accounts and identify if any data has been exfiltrated or any malicious code has been injected.
In Action 11, reimage the affected resources.
In Action 12, lift containment and bring systems back to operational standards.
In Action 13, complete the post-incident review before closing the task.