Windows Adfind Exe
Description
This search looks for the execution of adfind.exe
with command-line arguments that it uses by default. Specifically the filter or search functions. It also considers the arguments necessary like objectcategory, see readme for more details: https://www.joeware.net/freetools/tools/adfind/usage.htm. This has been seen used before by Wizard Spider, FIN6 and actors whom also launched SUNBURST. AdFind.exe is usually used a recon tool to enumare a domain controller.
Content Mapping
This content is not mapped to any local saved search. Add mapping
Help |
---|
Windows Adfind Exe HelpTo successfully implement this search, you need to be ingesting logs with the process name, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. |
Search |
---|
Open in Search |