Use the T1003 - Credential Dumping - Mimikatz DCsync playbook
Freigeben Version: Australia
Aktualisiert 12. März 2026
1 Minute Lesedauer
Use this playbook to investigate incidents suspected to be caused by Mimikatz DCSync. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the T1003 - Credential Dumping -
Mimikatz DCsync playbook.
Vorbereitungen
Role required:
sn_si.admin
flow_designer
Prozedur
When the playbook is triggered and starts executing, in Action 1, check the host activity on Splunk and look for any suspicious activities.
In Action 2, identify the owner of the server/endpoint/VM.
If the user is online, run the CrowdStrike EDR to gather a better scope of the system's activities.
In Action 3, gather information on the user's other account activities.
In Action 4, based on the investigation, verify if the server/endpoint/VM was ever used for credential dumping.
In Action 5, if the server/endpoint/VM wasn’t used for credential dumping, perform the following actions: