Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database
Flags Sysinternals ADExplorer running with -snapshot to export an Active Directory database to suspicious local directories.
FreeUnreviewedSigmahighv1
windows-process-creation-sysinternals-adexplorer-snapshot-exports-active-directo-ef61af62
title: "Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database"
id: 75bbe460-71ef-4532-9eb5-a1040e24cd2d
related:
- id: 9212f354-7775-4e28-9c9f-8f0a4544e664
type: derived
- id: ef61af62-bc74-4f58-b49b-626448227652
type: derived
status: test
description: This rule identifies execution of Sysinternals ADExplorer binaries when the command line includes the -snapshot flag and the snapshot output path is consistent with commonly abused writable locations. Saving a local copy of the Active Directory database can enable directory data discovery and downstream attacks such as credential-focused workflows (without requiring password hash extraction). Telemetry relies on Windows process creation events including Image/OriginalFileName, Product metadata, and full command-line and path content.
references:
- https://www.documentcloud.org/documents/5743766-Global-Threat-Report-2019.html
- https://learn.microsoft.com/de-de/sysinternals/downloads/adexplorer
- https://github.com/c3c/ADExplorerSnapshot.py/tree/f700904defac330802bbfedd1d8ffd9248f4ee24
- https://www.packetlabs.net/posts/scattered-spider-is-a-young-ransomware-gang-exploiting-large-corporations/
- https://www.nccgroup.com/us/research-blog/lapsus-recent-techniques-tactics-and-procedures/
- https://trustedsec.com/blog/adexplorer-on-engagements
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_sysinternals_adexplorer_susp_execution.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-03-14
modified: 2025-07-09
tags:
- attack.discovery
- attack.t1087.002
- attack.t1069.002
- attack.t1482
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith:
- \ADExp.exe
- \ADExplorer.exe
- \ADExplorer64.exe
- \ADExplorer64a.exe
- OriginalFileName: AdExp
- Description: Active Directory Editor
- Product: Sysinternals ADExplorer
selection_flag:
CommandLine|contains: snapshot
selection_paths:
CommandLine|contains:
- \Downloads\
- \Users\Public\
- \AppData\
- \Windows\Temp\
condition: all of selection_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule identifies execution of Sysinternals ADExplorer binaries when the command line includes the -snapshot flag and the snapshot output path is consistent with commonly abused writable locations. Saving a local copy of the Active Directory database can enable directory data discovery and downstream attacks such as credential-focused workflows (without requiring password hash extraction). Telemetry relies on Windows process creation events including Image/OriginalFileName, Product metadata, and full command-line and path content.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.