Skip to content
Threat Feed
low advisory

Detection of AdFind Active Directory Discovery Activity

AdFind.exe is a legitimate Active Directory query tool frequently repurposed by threat actors for post-exploitation reconnaissance in ransomware and criminal campaigns.

AdFind is a freely available command-line tool developed by Joeware for querying Active Directory (AD). While intended for administrative purposes, it is heavily leveraged by threat actors for post-exploitation reconnaissance. Threat groups, including those behind Trickbot, Ryuk, Maze, and FIN6 campaigns, utilize AdFind to map domain structures, identify high-value targets, and scope network subnets. Because the tool is dual-use, detection requires distinguishing legitimate administrative usage from anomalous execution, particularly when the process is invoked with common discovery arguments related to computers, user objects, or domain trusts. Defenders must establish baselines for authorized administrative activity to reduce noise when monitoring for unauthorized enumeration.

Impact

Successful reconnaissance with AdFind provides adversaries with the situational awareness necessary to move laterally through an environment, identify target systems for ransomware deployment, and locate accounts with elevated permissions. This reconnaissance phase is often a precursor to broader network compromise, data exfiltration, or the deployment of ransomware, significantly increasing the probability of a successful high-impact incident.

Recommendation

  • Implement the provided detection logic to identify AdFind execution with discovery-oriented arguments.
  • Establish a baseline for authorized administrators who legitimately use AdFind to minimize false positives.
  • Review historical process creation logs on systems where this alert triggers to investigate potential earlier stages of an attack chain.
  • If a suspicious execution is identified, perform host isolation and initiate credential audits to assess potential compromise of identified accounts.

Immediate actions

Deploy the provided Sigma detection rule to monitor for AdFind reconnaissance activity.

Detection Engineering 48h

Threat Hunt

Search historical logs for execution of AdFind.exe to establish a baseline of administrative behavior.

T1087 medium high confidence hunt now

Data: Process creation logs

Detection coverage 1

Detect AdFind Active Directory Discovery

low

Detects the execution of AdFind.exe with command-line arguments indicative of Active Directory enumeration.

sigma tactics: discovery techniques: T1016, T1087.002 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →