{"id":"T1482","name":"Domain Trust Discovery","url":"https://attack.mitre.org/techniques/T1482","tactics":["discovery"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0007","stix_id":"x-mitre-detection-strategy--3414f3b8-17a2-438c-8bbc-a261a04da8bc","name":"Detection of Domain Trust Discovery via API, Script, and CLI Enumeration","url":"https://attack.mitre.org/detectionstrategies/DET0007","analytics":[{"id":"AN0016","stix_id":"x-mitre-analytic--c3be6c4a-3b3d-4a37-a1d8-2c4df915a7aa","name":"Analytic 0016","description":"Adversary uses nltest, PowerShell, or Win32/.NET API to enumerate domain trust relationships (via DSEnumerateDomainTrusts, GetAllTrustRelationships, or LDAP queries), followed by discovery or authentication staging.","url":"https://attack.mitre.org/detectionstrategies/DET0007#AN0016","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:PowerShell","channel":"Get-ADTrust|GetAllTrustRelationships","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"},{"name":"WinEventLog:Security","channel":"EventCode=4662","data_component":"DC0071","data_component_name":"Active Directory Object Access","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"ParentImage","description":"Tune based on expected script hosts or authorized administrators invoking trust enumeration."},{"field":"TimeWindow","description":"Correlate enumeration + subsequent Kerberos activity or DC interaction within a bounded window."},{"field":"UserContext","description":"Prioritize detection for non-admin or unexpected user accounts performing enumeration."},{"field":"API_Name","description":"Flag uncommon or low-prevalence API calls like DSEnumerateDomainTrusts for inspection."}],"live":true,"detection_strategies":["DET0007"],"techniques":["T1482"]}],"live":true,"version":"1.0","techniques":["T1482"]}],"sigma_rules":[{"id":"02030f2f-6199-49ec-b258-ea71b07e03dc","title":"Malicious PowerShell Commandlets - ProcessCreation","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-01-02","modified":"2025-12-10","description":"Detects Commandlet names from well-known PowerShell exploitation frameworks","references":["https://adsecurity.org/?p=2921","https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries","https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1","https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1","https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1","https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1","https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/","https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/","https://github.com/calebstewart/CVE-2021-1675","https://github.com/BloodHoundAD/BloodHound/blob/0927441f67161cc6dc08a53c63ceb8e333f55874/Collectors/AzureHound.ps1","https://bloodhound.readthedocs.io/en/latest/data-collection/azurehound.html","https://github.com/HarmJ0y/DAMP","https://github.com/samratashok/nishang","https://github.com/DarkCoderSc/PowerRunAsSystem/","https://github.com/besimorhino/powercat","https://github.com/Kevin-Robertson/Powermad","https://github.com/adrecon/ADRecon","https://github.com/adrecon/AzureADRecon","https://github.com/sadshade/veeam-creds/blob/6010eaf31ba41011b58d6af3950cffbf6f5cea32/Veeam-Get-Creds.ps1","https://github.com/The-Viper-One/Invoke-PowerDPAPI/","https://github.com/Arno0x/DNSExfiltrator/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.discovery","attack.t1482","attack.t1087","attack.t1087.001","attack.t1087.002","attack.t1069.001","attack.t1069.002","attack.t1069","attack.t1059.001"],"path":"rules/windows/process_creation/proc_creation_win_powershell_malicious_cmdlets.yml","techniques":["T1482","T1087","T1087.001","T1087.002","T1069.001","T1069.002","T1069","T1059.001"],"cves":[]},{"id":"02773bed-83bf-469f-b7ff-e676e7d78bab","title":"BloodHound Collection Files","author":"C.J. May","status":"test","level":"high","date":"2022-08-09","modified":"2026-02-19","description":"Detects default file names outputted by the BloodHound collection tool SharpHound","references":["https://academy.hackthebox.com/course/preview/active-directory-bloodhound/bloodhound--data-collection"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.discovery","attack.t1087.001","attack.t1087.002","attack.t1482","attack.t1069.001","attack.t1069.002","attack.execution","attack.t1059.001"],"path":"rules/windows/file/file_event/file_event_win_bloodhound_collection.yml","techniques":["T1087.001","T1087.002","T1482","T1069.001","T1069.002","T1059.001"],"cves":[]},{"id":"0a1255c5-d732-4b62-ac02-b5152d34fb83","title":"ADExplorer Writing Complete AD Snapshot Into .dat File","author":"Arnim Rupp (Nextron Systems), Thomas Patzke","status":"experimental","level":"medium","date":"2025-07-09","modified":null,"description":"Detects the dual use tool ADExplorer writing a complete AD snapshot into a .dat file. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.","references":["https://learn.microsoft.com/de-de/sysinternals/downloads/adexplorer","https://github.com/c3c/ADExplorerSnapshot.py/tree/f700904defac330802bbfedd1d8ffd9248f4ee24","https://www.packetlabs.net/posts/scattered-spider-is-a-young-ransomware-gang-exploiting-large-corporations/","https://www.nccgroup.com/us/research-blog/lapsus-recent-techniques-tactics-and-procedures/","https://trustedsec.com/blog/adexplorer-on-engagements"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.discovery","attack.t1087.002","attack.t1069.002","attack.t1482"],"path":"rules/windows/file/file_event/file_event_win_sysinternals_adexplorer_dump_written.yml","techniques":["T1087.002","T1069.002","T1482"],"cves":[]},{"id":"31d68132-4038-47c7-8f8e-635a39a7c174","title":"Potential Active Directory Reconnaissance/Enumeration Via LDAP","author":"Adeem Mawani","status":"test","level":"medium","date":"2021-06-22","modified":"2025-07-04","description":"Detects potential Active Directory enumeration via LDAP","references":["https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/hunting-for-reconnaissance-activities-using-ldap-search-filters/ba-p/824726","https://github.com/PowerShellMafia/PowerSploit/blob/d943001a7defb5e0d1657085a77a0e78609be58f/Recon/PowerView.ps1","https://github.com/BloodHoundAD/SharpHound3/blob/7d96b991b1887ff50349ce59c80980bc0d95c86a/SharpHound3/LdapBuilder.cs","https://medium.com/falconforce/falconfriday-detecting-active-directory-data-collection-0xff21-c22d1a57494c","https://github.com/fox-it/BloodHound.py/blob/d65eb614831cd30f26028ccb072f5e77ca287e0b/bloodhound/ad/domain.py#L427","https://ipurple.team/2024/07/15/sharphound-detection/"],"logsource":{"product":"windows","service":"ldap"},"tags":["attack.discovery","attack.t1069.002","attack.t1087.002","attack.t1482"],"path":"rules/windows/builtin/ldap/win_ldap_recon.yml","techniques":["T1069.002","T1087.002","T1482"],"cves":[]},{"id":"3bad990e-4848-4a78-9530-b427d854aac0","title":"Domain Trust Discovery Via Dsquery","author":"E.M. Anhaus, Tony Lambert, oscd.community, omkar72","status":"test","level":"medium","date":"2019-10-24","modified":"2023-02-02","description":"Detects execution of \"dsquery.exe\" for domain trust discovery","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1482/T1482.md","https://posts.specterops.io/an-introduction-to-manual-active-directory-querying-with-dsquery-and-ldapsearch-84943c13d7eb?gi=41b97a644843"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1482"],"path":"rules/windows/process_creation/proc_creation_win_dsquery_domain_trust_discovery.yml","techniques":["T1482"],"cves":[]},{"id":"5cc90652-4cbd-4241-aa3b-4b462fa5a248","title":"Potential Recon Activity Via Nltest.EXE","author":"Craig Young, oscd.community, Georg Lauenstein","status":"test","level":"medium","date":"2021-07-24","modified":"2023-12-15","description":"Detects nltest commands that can be used for information discovery","references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11)","https://thedfirreport.com/2021/08/16/trickbot-leads-up-to-fake-1password-installation/","https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/","https://book.hacktricks.xyz/windows/basic-cmd-for-pentesters","https://research.nccgroup.com/2022/08/19/back-in-black-unlocking-a-lockbit-3-0-ransomware-attack/","https://eqllib.readthedocs.io/en/latest/analytics/03e231a6-74bc-467a-acb1-e5676b0fb55e.html","https://redcanary.com/blog/how-one-hospital-thwarted-a-ryuk-ransomware-outbreak/","https://github.com/redcanaryco/atomic-red-team/blob/5360c9d9ffa3b25f6495f7a16e267b719eba2c37/atomics/T1482/T1482.md#atomic-test-2---windows---discover-domain-trusts-with-nltest"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1016","attack.t1482"],"path":"rules/windows/process_creation/proc_creation_win_nltest_recon.yml","techniques":["T1016","T1482"],"cves":[]},{"id":"69ca006d-b9a9-47f5-80ff-ecd4d25d481a","title":"HackTool - TruffleSnout Execution","author":"frack113","status":"test","level":"high","date":"2022-08-20","modified":"2023-02-13","description":"Detects the use of TruffleSnout.exe an iterative AD discovery toolkit for offensive operators, situational awareness and targeted low noise enumeration.","references":["https://github.com/redcanaryco/atomic-red-team/blob/40b77d63808dd4f4eafb83949805636735a1fd15/atomics/T1482/T1482.md","https://github.com/dsnezhkov/TruffleSnout","https://github.com/dsnezhkov/TruffleSnout/blob/7c2f22e246ef704bc96c396f66fa854e9ca742b9/TruffleSnout/Docs/USAGE.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1482"],"path":"rules/windows/process_creation/proc_creation_win_hktl_trufflesnout.yml","techniques":["T1482"],"cves":[]},{"id":"7d0d0329-0ef1-4e84-a9f5-49500f9d7c6c","title":"Malicious PowerShell Commandlets - PoshModule","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-01-20","modified":"2025-12-10","description":"Detects Commandlet names from well-known PowerShell exploitation frameworks","references":["https://adsecurity.org/?p=2921","https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries","https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1","https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1","https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1","https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1","https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/","https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/","https://github.com/calebstewart/CVE-2021-1675","https://github.com/BloodHoundAD/BloodHound/blob/0927441f67161cc6dc08a53c63ceb8e333f55874/Collectors/AzureHound.ps1","https://bloodhound.readthedocs.io/en/latest/data-collection/azurehound.html","https://github.com/HarmJ0y/DAMP","https://github.com/samratashok/nishang","https://github.com/DarkCoderSc/PowerRunAsSystem/","https://github.com/besimorhino/powercat","https://github.com/Kevin-Robertson/Powermad","https://github.com/adrecon/ADRecon","https://github.com/adrecon/AzureADRecon","https://github.com/sadshade/veeam-creds/blob/6010eaf31ba41011b58d6af3950cffbf6f5cea32/Veeam-Get-Creds.ps1","https://github.com/The-Viper-One/Invoke-PowerDPAPI/","https://github.com/Arno0x/DNSExfiltrator/"],"logsource":{"product":"windows","category":"ps_module"},"tags":["attack.execution","attack.discovery","attack.t1482","attack.t1087","attack.t1087.001","attack.t1087.002","attack.t1069.001","attack.t1069.002","attack.t1069","attack.t1059.001"],"path":"rules/windows/powershell/powershell_module/posh_pm_malicious_commandlets.yml","techniques":["T1482","T1087","T1087.001","T1087.002","T1069.001","T1069.002","T1069","T1059.001"],"cves":[]},{"id":"89819aa4-bbd6-46bc-88ec-c7f7fe30efa6","title":"Malicious PowerShell Commandlets - ScriptBlock","author":"Sean Metcalf, Florian Roth, Bartlomiej Czyz @bczyz1, oscd.community, Nasreddine Bencherchali, Tim Shelton, Mustafa Kaan Demir, Georg Lauenstein, Max Altgelt, Tobias Michalski, Austin Songer","status":"test","level":"high","date":"2017-03-05","modified":"2025-12-10","description":"Detects Commandlet names from well-known PowerShell exploitation frameworks","references":["https://adsecurity.org/?p=2921","https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries","https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1","https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1","https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1","https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1","https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/","https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/","https://github.com/calebstewart/CVE-2021-1675","https://github.com/BloodHoundAD/BloodHound/blob/0927441f67161cc6dc08a53c63ceb8e333f55874/Collectors/AzureHound.ps1","https://bloodhound.readthedocs.io/en/latest/data-collection/azurehound.html","https://github.com/HarmJ0y/DAMP","https://github.com/samratashok/nishang","https://github.com/DarkCoderSc/PowerRunAsSystem/","https://github.com/besimorhino/powercat","https://github.com/Kevin-Robertson/Powermad","https://github.com/adrecon/ADRecon","https://github.com/adrecon/AzureADRecon","https://github.com/The-Viper-One/Invoke-PowerDPAPI/","https://github.com/Arno0x/DNSExfiltrator/"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.execution","attack.discovery","attack.t1482","attack.t1087","attack.t1087.001","attack.t1087.002","attack.t1069.001","attack.t1069.002","attack.t1069","attack.t1059.001"],"path":"rules/windows/powershell/powershell_script/posh_ps_malicious_commandlets.yml","techniques":["T1482","T1087","T1087.001","T1087.002","T1069.001","T1069.002","T1069","T1059.001"],"cves":[]},{"id":"903076ff-f442-475a-b667-4f246bcc203b","title":"Nltest.EXE Execution","author":"Arun Chauhan","status":"test","level":"low","date":"2023-02-03","modified":null,"description":"Detects nltest commands that can be used for information discovery","references":["https://jpcertcc.github.io/ToolAnalysisResultSheet/details/nltest.htm"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1016","attack.t1018","attack.t1482"],"path":"rules/windows/process_creation/proc_creation_win_nltest_execution.yml","techniques":["T1016","T1018","T1482"],"cves":[]},{"id":"9212f354-7775-4e28-9c9f-8f0a4544e664","title":"Active Directory Database Snapshot Via ADExplorer","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-03-14","modified":"2025-07-09","description":"Detects the execution of Sysinternals ADExplorer with the \"-snapshot\" flag in order to save a local copy of the active directory database. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.","references":["https://www.documentcloud.org/documents/5743766-Global-Threat-Report-2019.html","https://learn.microsoft.com/de-de/sysinternals/downloads/adexplorer","https://github.com/c3c/ADExplorerSnapshot.py/tree/f700904defac330802bbfedd1d8ffd9248f4ee24","https://www.packetlabs.net/posts/scattered-spider-is-a-young-ransomware-gang-exploiting-large-corporations/","https://www.nccgroup.com/us/research-blog/lapsus-recent-techniques-tactics-and-procedures/","https://trustedsec.com/blog/adexplorer-on-engagements"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1087.002","attack.t1069.002","attack.t1482"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_adexplorer_execution.yml","techniques":["T1087.002","T1069.002","T1482"],"cves":[]},{"id":"9a132afa-654e-11eb-ae93-0242ac130002","title":"PUA - AdFind Suspicious Execution","author":"Janantha Marasinghe (https://github.com/blueteam0ps), FPT.EagleEye Team, omkar72, oscd.community","status":"test","level":"high","date":"2021-02-02","modified":"2025-10-24","description":"Detects AdFind execution with common flags seen used during attacks","references":["https://www.joeware.net/freetools/tools/adfind/","https://thedfirreport.com/2020/05/08/adfind-recon/","https://thedfirreport.com/2021/01/11/trickbot-still-alive-and-well/","https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/","https://social.technet.microsoft.com/wiki/contents/articles/7535.adfind-command-examples.aspx","https://github.com/center-for-threat-informed-defense/adversary_emulation_library/blob/bf62ece1c679b07b5fb49c4bae947fe24c81811f/fin6/Emulation_Plan/Phase1.md","https://github.com/redcanaryco/atomic-red-team/blob/0f229c0e42bfe7ca736a14023836d65baa941ed2/atomics/T1087.002/T1087.002.md#atomic-test-7---adfind---enumerate-active-directory-user-objects"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1018","attack.t1087.002","attack.t1482","attack.t1069.002","stp.1u"],"path":"rules/windows/process_creation/proc_creation_win_pua_adfind_susp_usage.yml","techniques":["T1018","T1087.002","T1482","T1069.002"],"cves":[]},{"id":"a21bcd7e-38ec-49ad-b69a-9ea17e69509e","title":"DNS Server Discovery Via LDAP Query","author":"frack113","status":"test","level":"low","date":"2022-08-20","modified":"2023-09-18","description":"Detects DNS server discovery via LDAP query requests from uncommon applications","references":["https://github.com/redcanaryco/atomic-red-team/blob/980f3f83fd81f37c1ca9c02dccfd1c3d9f9d0841/atomics/T1016/T1016.md#atomic-test-9---dns-server-discovery-using-nslookup","https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/7fcdce70-5205-44d6-9c3a-260e616a2f04"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.discovery","attack.t1482"],"path":"rules/windows/dns_query/dns_query_win_dns_server_discovery_via_ldap_query.yml","techniques":["T1482"],"cves":[]},{"id":"b2317cfa-4a47-4ead-b3ff-297438c0bc2d","title":"HackTool - SharpView Execution","author":"frack113","status":"test","level":"high","date":"2021-12-10","modified":"2023-02-14","description":"Adversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems","references":["https://github.com/tevora-threat/SharpView/","https://github.com/PowerShellMafia/PowerSploit/blob/d943001a7defb5e0d1657085a77a0e78609be58f/Recon/PowerView.ps1","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1049/T1049.md#atomic-test-4---system-discovery-using-sharpview"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1049","attack.t1069.002","attack.t1482","attack.t1135","attack.t1033"],"path":"rules/windows/process_creation/proc_creation_win_hktl_sharpview.yml","techniques":["T1049","T1069.002","T1482","T1135","T1033"],"cves":[]},{"id":"df55196f-f105-44d3-a675-e9dfb6cc2f2b","title":"Renamed AdFind Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-08-21","modified":"2025-02-26","description":"Detects the use of a renamed Adfind.exe. AdFind continues to be seen across majority of breaches. It is used to domain trust discovery to plan out subsequent steps in the attack chain.","references":["https://www.joeware.net/freetools/tools/adfind/","https://thedfirreport.com/2020/05/08/adfind-recon/","https://thedfirreport.com/2021/01/11/trickbot-still-alive-and-well/","https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/","https://social.technet.microsoft.com/wiki/contents/articles/7535.adfind-command-examples.aspx","https://github.com/center-for-threat-informed-defense/adversary_emulation_library/blob/bf62ece1c679b07b5fb49c4bae947fe24c81811f/fin6/Emulation_Plan/Phase1.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1018","attack.t1087.002","attack.t1482","attack.t1069.002"],"path":"rules/windows/process_creation/proc_creation_win_renamed_adfind.yml","techniques":["T1018","T1087.002","T1482","T1069.002"],"cves":[]},{"id":"ef61af62-bc74-4f58-b49b-626448227652","title":"Suspicious Active Directory Database Snapshot Via ADExplorer","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-03-14","modified":"2025-07-09","description":"Detects the execution of Sysinternals ADExplorer with the \"-snapshot\" flag in order to save a local copy of the active directory database to a suspicious directory. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.","references":["https://www.documentcloud.org/documents/5743766-Global-Threat-Report-2019.html","https://learn.microsoft.com/de-de/sysinternals/downloads/adexplorer","https://github.com/c3c/ADExplorerSnapshot.py/tree/f700904defac330802bbfedd1d8ffd9248f4ee24","https://www.packetlabs.net/posts/scattered-spider-is-a-young-ransomware-gang-exploiting-large-corporations/","https://www.nccgroup.com/us/research-blog/lapsus-recent-techniques-tactics-and-procedures/","https://trustedsec.com/blog/adexplorer-on-engagements"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1087.002","attack.t1069.002","attack.t1482"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_adexplorer_susp_execution.yml","techniques":["T1087.002","T1069.002","T1482"],"cves":[]},{"id":"f376c8a7-a2d0-4ddc-aa0c-16c17236d962","title":"HackTool - Bloodhound/Sharphound Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-12-20","modified":"2023-02-04","description":"Detects command line parameters used by Bloodhound and Sharphound hack tools","references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/BloodHoundAD/SharpHound"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1087.001","attack.t1087.002","attack.t1482","attack.t1069.001","attack.t1069.002","attack.execution","attack.t1059.001"],"path":"rules/windows/process_creation/proc_creation_win_hktl_bloodhound_sharphound.yml","techniques":["T1087.001","T1087.002","T1482","T1069.001","T1069.002","T1059.001"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2023-22952","state":"stale","mapping_types":["secondary_impact"]},{"cveID":"CVE-2022-41082","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}