{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/tool-usage/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["discovery","active-directory","tool-usage"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eSOAPHound is a .NET-based offensive security tool designed to collect sensitive data from Active Directory (AD) environments. It interacts with Active Directory Web Services (ADWS) to perform enumeration and data exfiltration. The tool is commonly used during the reconnaissance and discovery phases of an attack to gather information such as domain structure, object properties, and certificate templates. Defenders should monitor for the execution of this tool, as its presence often signals an attempt to map the network or identify targets for privilege escalation. The tool supports various dumping operations, including certificate and DNS enumeration, which are indicative of an active adversary attempting to gain deeper visibility into the internal infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful use of SOAPHound allows unauthorized actors to perform comprehensive enumeration of Active Directory environments, facilitating lateral movement and target identification. This compromises the integrity and confidentiality of AD services, potentially leading to domain-wide security risks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor for process creation events associated with SOAPHound command-line arguments.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for ADWS traffic or abnormal LDAP queries originating from non-administrative endpoints.\u003c/li\u003e\n\u003cli\u003eEstablish baseline monitoring for .NET assembly execution to identify the usage of unauthorized administrative tools.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T12:39:49Z","date_published":"2026-09-03T12:39:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-soaphound-execution/","summary":"Detection of the .NET-based SOAPHound utility used for unauthorized extraction of Active Directory data via Active Directory Web Services.","title":"Detection of SOAPHound Active Directory Collection Tool","url":"https://feed.craftedsignal.io/briefs/2026-09-soaphound-execution/"}],"language":"en","title":"CraftedSignal Threat Feed - Tool-Usage","version":"https://jsonfeed.org/version/1.1"}