AdFind
MITRE ATT&CK: S0552 View on attack.mitre.org
Aliases: AdFind
- Operating systems
- windows
- Last IoC activity
- 2026-04-24 08:14:57
- Profile updated
- 2026-07-07 12:48:44
Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Context
AdFind is a free command-line query tool that can be used for gathering information from Active Directory.
Detection coverage
- 2 YARA rules
- 76 Sigma rules
Malware & tools used
- Domain Trust Discovery (attack-pattern)
- Domain Groups (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Remote System Discovery (attack-pattern)
- Domain Account (attack-pattern)
Used by threat actors
- C0015 (campaign)
- SolarWinds Compromise (campaign)
- Lotus Blossom (threat-actor)
- Wizard Spider (threat-actor)
- INC Ransom (threat-actor)
- Mustang Panda (threat-actor)
- TA505 (threat-actor)
- APT29 (threat-actor)
- Play (threat-actor)
- FIN6 (threat-actor)
- menuPass (threat-actor)
- FIN7 (threat-actor)
- Akira (threat-actor)
- BlackByte (threat-actor)
Detection rules
- DITEKSHEN_INDICATOR_TOOL_REC_Adfind (yara-rule)
- SEKOIA_Recotool_Adfind_Strings (yara-rule)
Reports & references
- Mandiant — Pick Six Intercepting A Fin6 Intrusion (report)
- Mandiant — A Nasty Trick From Credential Theft Malware To Business Disruption (report)
- redcanary.com — How One Hospital Thwarted A Ryuk Ransomware Outbreak (report)
- MITRE ATT&CK — S0552 (report)