Detection of AdFind Active Directory Discovery Activity
AdFind.exe is a legitimate Active Directory query tool frequently repurposed by threat actors for post-exploitation reconnaissance in ransomware and criminal campaigns.
AdFind is a freely available command-line tool developed by Joeware for querying Active Directory (AD). While intended for administrative purposes, it is heavily leveraged by threat actors for post-exploitation reconnaissance. Threat groups, including those behind Trickbot, Ryuk, Maze, and FIN6 campaigns, utilize AdFind to map domain structures, identify high-value targets, and scope network subnets. Because the tool is dual-use, detection requires distinguishing legitimate administrative usage from anomalous execution, particularly when the process is invoked with common discovery arguments related to computers, user objects, or domain trusts. Defenders must establish baselines for authorized administrative activity to reduce noise when monitoring for unauthorized enumeration.
Impact
Successful reconnaissance with AdFind provides adversaries with the situational awareness necessary to move laterally through an environment, identify target systems for ransomware deployment, and locate accounts with elevated permissions. This reconnaissance phase is often a precursor to broader network compromise, data exfiltration, or the deployment of ransomware, significantly increasing the probability of a successful high-impact incident.
Recommendation
- Implement the provided detection logic to identify AdFind execution with discovery-oriented arguments.
- Establish a baseline for authorized administrators who legitimately use AdFind to minimize false positives.
- Review historical process creation logs on systems where this alert triggers to investigate potential earlier stages of an attack chain.
- If a suspicious execution is identified, perform host isolation and initiate credential audits to assess potential compromise of identified accounts.
Immediate actions
Deploy the provided Sigma detection rule to monitor for AdFind reconnaissance activity.
Threat Hunt
Search historical logs for execution of AdFind.exe to establish a baseline of administrative behavior.
Data: Process creation logs
Detection coverage 1
Detect AdFind Active Directory Discovery
lowDetects the execution of AdFind.exe with command-line arguments indicative of Active Directory enumeration.
Detection queries are available on the platform. Get full rules →