Windows File Events: ADExplorer .dat Snapshot Written by ADExp.exe or ADExplorer.exe

Detects ADExplorer exporting an AD snapshot by writing .dat files on Windows.

FreeReviewedSigma · Medium · v2
Product
windows
Category
file_event
Author
Arnim Rupp (Nextron Systems), Thomas Patzke (SigmaHQ), DRL 1.1
Published
2025-07-09
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies instances where ADExplorer executables (ADExp.exe, ADExplorer.exe, ADExplorer64.exe, ADExplorer64a.exe) write a complete Active Directory snapshot to a .dat file. Attackers can use these snapshots to collect directory data for downstream activities such as reconnaissance or password-related targeting, and the exported metadata may support social engineering even without password hashes. Detection relies on Windows file create/write events that include the process image path and the target filename ending in .dat.

Related detections9 linkedT1069.002 — drag to rearrange
Windows: Sysinternals ADExplorer invoked with snapshot flag to create AD database snapshot
Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database
Windows PowerShell module commandlet names matching known exploitation and post-exploitation tooling
Windows Process Creation: Suspicious PowerShell Commandlets Used by Known Exploitation Tools
Windows Process Creation: Renamed AdFind.exe Executions
Windows file creation for SharpHound/BloodHound collection output filenames
Windows LDAP Client Event ID 30 Active Directory enumeration via LDAP search filters
Windows Process Creation: AdFind Executed with Suspicious Recon Flags
Windows Process Execution of Bloodhound/SharpHound Command-Line Collection Options
Windows File Events: ADExplorer .dat Snapshot Written by ADExp.exe or ADExplorer.exe
Pivot detection · T1069.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.