AdFind

MITRE ATT&CK: S0552 View on attack.mitre.org

Aliases: AdFind

Operating systems
windows
Last IoC activity
2026-04-24 08:14:57
Profile updated
2026-07-07 12:48:44

Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Context

AdFind is a free command-line query tool that can be used for gathering information from Active Directory.

Detection coverage

  • 2 YARA rules
  • 76 Sigma rules

Malware & tools used

  • Domain Trust Discovery (attack-pattern)
  • Domain Groups (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Domain Account (attack-pattern)

Used by threat actors

Detection rules

  • DITEKSHEN_INDICATOR_TOOL_REC_Adfind (yara-rule)
  • SEKOIA_Recotool_Adfind_Strings (yara-rule)

Reports & references

  • Mandiant — Pick Six Intercepting A Fin6 Intrusion (report)
  • Mandiant — A Nasty Trick From Credential Theft Malware To Business Disruption (report)
  • redcanary.com — How One Hospital Thwarted A Ryuk Ransomware Outbreak (report)
  • MITRE ATT&CK — S0552 (report)

External references