PUA - AdFind Suspicious Execution

 Original Source: [Sigma source]
Title: PUA - AdFind Suspicious Execution
Status: test
Description:Detects AdFind execution with common flags seen used during attacks
References:
  -https://www.joeware.net/freetools/tools/adfind/
  -https://thedfirreport.com/2020/05/08/adfind-recon/
  -https://thedfirreport.com/2021/01/11/trickbot-still-alive-and-well/
  -https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/
  -https://social.technet.microsoft.com/wiki/contents/articles/7535.adfind-command-examples.aspx
  -https://github.com/center-for-threat-informed-defense/adversary_emulation_library/blob/bf62ece1c679b07b5fb49c4bae947fe24c81811f/fin6/Emulation_Plan/Phase1.md
  -https://github.com/redcanaryco/atomic-red-team/blob/0f229c0e42bfe7ca736a14023836d65baa941ed2/atomics/T1087.002/T1087.002.md#atomic-test-7---adfind---enumerate-active-directory-user-objects
Author: Janantha Marasinghe (https://github.com/blueteam0ps), FPT.EagleEye Team, omkar72, oscd.community
Date: 2021-02-02
modified:2025-10-24
Tags:
  • -'attack.discovery'
  • -'attack.t1018'
  • -'attack.t1087.002'
  • -'attack.t1482'
  • -'attack.t1069.002'
  • -'stp.1u'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains:
      -'domainlist'
      -'trustdmp'
      -'dcmodes'
      -'adinfo'
      -'-sc dclist'
      -'computer_pwdnotreqd'
      -'objectcategory='
      -'-subnets -f'
      -'name="Domain Admins"'
      -'-sc u:'
      -'domainncs'
      -'dompol'
      -' oudmp '
      -'subnetdmp'
      -'gpodmp'
      -'fspdmp'
      -'users_noexpire'
      -'computers_active'
      -'computers_pwdnotreqd'

  condition:selection
Falsepositives:
  -Legitimate admin activity
Level: high