dsquery

MITRE ATT&CK: S0105 View on attack.mitre.org

Aliases: dsquery.exe, dsquery

Operating systems
windows
Profile updated
2026-07-07 15:32:18

Context

dsquery is a command-line utility that can be used to query Active Directory for information from a system within a domain. It is typically installed only on Windows Server versions but can be installed on non-server variants through the Microsoft-provided Remote Server Administration Tools bundle.

Detection coverage

  • 82 Sigma rules

Malware & tools used

  • Domain Account (attack-pattern)
  • Domain Trust Discovery (attack-pattern)
  • Domain Groups (attack-pattern)
  • System Information Discovery (attack-pattern)

Used by threat actors

  • Operation CuckooBees (campaign)
  • C0017 (campaign)
  • Operation Wocao (campaign)
  • APT41 (threat-actor)
  • FIN8 (threat-actor)

Reports & references

  • MITRE ATT&CK — S0105 (report)
  • Microsoft — Cc732952 (report)

External references