AdFind is a legitimate command-line utility for querying Microsoft Active Directory and other directory services. It is frequently abused after compromise for Active Directory reconnaissance, including enumeration of domain users, groups, computers, organizational units, domain trusts, and network configuration. AdFind has appeared in espionage, ransomware, and financially motivated intrusions involving actors and operations variously tracked as Earth Krahang, REF2924, Dark Halo/NOBELIUM, UNC2447, Andariel, and affiliates of ransomware families including Akira, BlackCat, Nefilim, NetWalker, ProLock, and Sodinokibi. Operators may rename the utility to masquerade as legitimate software. Its output can identify privileged accounts, domain relationships, and reachable systems that support subsequent credential theft and lateral movement. AdFind is principally used in Windows Active Directory enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Along with TFirewall, we observed that the attacker used the free tool AdFind.
The attacker also made use of a file called sqlceip.exe, which upon first glance might appear as the legitimate version of SQL Server Telemetry Client provided by Microsoft. However, Volexity determined this tool was actually a version of AdFind from joeware.net. AdFind is a command-line tool used for querying and extracting data from Active Directory.
The attacker also made use of a file called sqlceip.exe, which upon first glance might appear as the legitimate version of SQL Server Telemetry Client provided by Microsoft. However, Volexity determined this tool was actually a version of AdFind from joeware.net. AdFind is a command-line tool used for querying and extracting data from Active Directory.
AdFind has the ability to query Active Directory for computers.
...open-source and dual-use tools as used and/or customized by the actors: ... AdFind ...
13 distinct techniques documented for this family, organized by ATT&CK tactic.
BlackByte used AdFind during operations. Mustang Panda has utilized AdFind for enumerating domain groups, users, and computers. Lotus Blossom has used AdFind to query Active Directory in victim environments.
LockBit affiliates use SoftPerfect Network Scanner, Advanced IP Scanner, or Advanced Port Scanner to scan target networks.
AdFind is a command-line LDAP query tool abused by virtually every major IAB and ransomware operator for Active Directory enumeration.
Common initial discovery tools include Windows built-in utilities (net.exe, nltest.exe, systeminfo, ipconfig, whoami, etc)
Mustang Panda has utilized AdFind for enumerating domain groups, users, and computers.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Active Directory reconnaissance tool used to enumerate and query AD objects; leveraged post-compromise to map environments and identify targets for lateral movement.
Active Directory enumeration tool abused by Play/Balloonfly for discovery in victim environments prior to ransomware deployment.
Active Directory discovery tool used to enumerate directory objects/trusts to support targeting and lateral movement.
AdFind is a directory-querying tool used for Active Directory enumeration and network/domain discovery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.