---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Playbook for T1003 - Credential Dumping - Mimikatz DCSync

# Playbook for T1003 - Credential Dumping - Mimikatz DCSync {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

This playbook provides systematic remediation steps to investigate incidents suspected to be caused by Mimikatz DCSync. This playbook triggers when one of the Mimikatz functions (lsadump::dcsync) is used. The
function is typically used on attacked Domain Controllers (DC).

Mimikatz is a popular hacking tool that enables users to issue commands that help retrieve confidential data from the attacked system. The confidential data includes passwords, their hashes, and others.  
Note:  
This is a high-fidelity alert, which is assumed to be rarely triggered. When it triggers, you should notify a senior team member or Manager immediately.
* **[Set up the T1003 - Credential Dumping - Mimikatz DCsync playbook](https://servicenow-prod.fluidtopics.net/JdtbOghqtUpFrz6t3Qp1pw)**   
  Use the following steps to set up the T1003 - Credential Dumping - Mimikatz DCsync playbook.
* **[Use the T1003 - Credential Dumping - Mimikatz DCsync playbook](https://servicenow-prod.fluidtopics.net/Q2tGHhuOyXSVULEBm29qUA)**   
  Use this playbook to investigate incidents suspected to be caused by Mimikatz DCSync. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the T1003 - Credential Dumping - Mimikatz DCsync playbook.

