This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
PUA - AdFind Suspicious Execution
Original Source:
[Sigma source]
Title:
PUA - AdFind Suspicious Execution
Status:
test
Description:
Detects AdFind execution with common flags seen used during attacks
References:
-https://www.joeware.net/freetools/tools/adfind/
-https://thedfirreport.com/2020/05/08/adfind-recon/
-https://thedfirreport.com/2021/01/11/trickbot-still-alive-and-well/
-https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/
-https://social.technet.microsoft.com/wiki/contents/articles/7535.adfind-command-examples.aspx
-https://github.com/center-for-threat-informed-defense/adversary_emulation_library/blob/bf62ece1c679b07b5fb49c4bae947fe24c81811f/fin6/Emulation_Plan/Phase1.md
-https://github.com/redcanaryco/atomic-red-team/blob/0f229c0e42bfe7ca736a14023836d65baa941ed2/atomics/T1087.002/T1087.002.md#atomic-test-7---adfind---enumerate-active-directory-user-objects
Author:
Janantha Marasinghe (https://github.com/blueteam0ps), FPT.EagleEye Team, omkar72, oscd.community
Date:
2021-02-02
modified:
2025-10-24
Tags:
-'attack.discovery'
-'attack.t1018'
-'attack.t1087.002'
-'attack.t1482'
-'attack.t1069.002'
-'stp.1u'
Logsource:
category: process_creation
product: windows
Detection:
selection:
CommandLine|contains
:
-'domainlist'
-'trustdmp'
-'dcmodes'
-'adinfo'
-'-sc dclist'
-'computer_pwdnotreqd'
-'objectcategory='
-'-subnets -f'
-'name="Domain Admins"'
-'-sc u:'
-'domainncs'
-'dompol'
-' oudmp '
-'subnetdmp'
-'gpodmp'
-'fspdmp'
-'users_noexpire'
-'computers_active'
-'computers_pwdnotreqd'
condition
:
selection
Falsepositives:
-Legitimate admin activity
Level:
high