Actor
medium
advisory
AdFind.exe Execution with Reconnaissance Arguments
2 rules 1 TTP 1 IOCThis rule detects the execution of AdFind.exe with specific command-line arguments used for reconnaissance, often associated with threat actors like Wizard Spider, FIN6, and groups linked to SUNBURST, who use it to enumerate domain controllers.
AdFind +2
Conti
+3
active-directory
reconnaissance
discovery
2r
1t
1i
low
threat
AdFind Active Directory Reconnaissance Activity
3 rules 5 TTPsAdFind.exe, a legitimate Active Directory query tool, is commonly abused by threat actors such as Trickbot, Ryuk, Maze, and FIN6 for post-exploitation Active Directory reconnaissance, enabling enumeration of objects like computers, people, subnets, and domain information.
Active Directory
Trickbot
+3
adfind
active-directory
reconnaissance
discovery
windows
3r
5t
low
threat
AdFind Tool Used for Active Directory Reconnaissance
2 rules 5 TTPsThe execution of AdFind.exe, an Active Directory query tool, is often used by threat actors for post-exploitation Active Directory reconnaissance, as observed in campaigns involving Trickbot, Ryuk, Maze, and FIN6.
Elastic Defend
FIN6
adfind
active-directory
reconnaissance
windows
2r
5t