Actor
medium
threat
PowerShell Directory Enumeration via MAZE Ransomware Tactics
1 rule 1 TTPDetection of PowerShell scripts utilizing specific cmdlets to recursively enumerate file system directories, a technique historically associated with MAZE ransomware discovery operations.
MAZE
discovery
ransomware
powershell
windows
ma-ze
1r
1t
low
threat
AdFind Active Directory Reconnaissance Activity
3 rules 5 TTPsAdFind.exe, a legitimate Active Directory query tool, is commonly abused by threat actors such as Trickbot, Ryuk, Maze, and FIN6 for post-exploitation Active Directory reconnaissance, enabling enumeration of objects like computers, people, subnets, and domain information.
Active Directory
Trickbot
+3
adfind
active-directory
reconnaissance
discovery
windows
3r
5t