Suspicious ADExplorer Writing Complete AD Snapshot Into .dat File (via file_event)
This rule detects the dual use tool ADExplorer writing a complete AD snapshot into a .dat file. This can be used by adversaries to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
SigmamediumWindowsv1
sigma
suspicious-adexplorer-writing-complete-ad-snapshot-into-dat-file-via-file-event
title: Suspicious ADExplorer Writing Complete AD Snapshot Into .dat File (via file_event)
id: 8ed15eca-8e28-5b22-ac03-32fb25ddc04a
status: stable
description: This rule detects the dual use tool ADExplorer writing a complete AD snapshot into a .dat file. This can be used by adversaries to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
references:
- https://attack.mitre.org/techniques/T1482/
- https://attack.mitre.org/techniques/T1069/002/
- https://attack.mitre.org/techniques/T1087/002/
- https://learn.microsoft.com/de-de/sysinternals/downloads/adexplorer
- https://github.com/c3c/ADExplorerSnapshot.py/tree/f700904defac330802bbfedd1d8ffd9248f4ee24
- https://www.packetlabs.net/posts/scattered-spider-is-a-young-ransomware-gang-exploiting-large-corporations/
- https://www.nccgroup.com/us/research-blog/lapsus-recent-techniques-tactics-and-procedures/
- https://trustedsec.com/blog/adexplorer-on-engagements
author: Huntrule Team
date: 2026-05-26
tags:
- attack.discovery
- attack.t1087.002
- attack.t1069.002
- attack.t1482
logsource:
category: file_event
product: windows
detection:
selection:
Image|endswith:
- '\ADExp.exe'
- '\ADExplorer.exe'
- '\ADExplorer64.exe'
- '\ADExplorer64a.exe'
TargetFilename|endswith: '.dat'
condition: selection
falsepositives:
- Unknown
level: medium
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.