Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database

Flags Sysinternals ADExplorer running with -snapshot to export an Active Directory database to suspicious local directories.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-03-14
Updated
2026-07-30

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies execution of Sysinternals ADExplorer binaries when the command line includes the -snapshot flag and the snapshot output path is consistent with commonly abused writable locations. Saving a local copy of the Active Directory database can enable directory data discovery and downstream attacks such as credential-focused workflows (without requiring password hash extraction). Telemetry relies on Windows process creation events including Image/OriginalFileName, Product metadata, and full command-line and path content.

Related detections9 linkedT1069.002 — drag to rearrange
Windows File Events: ADExplorer .dat Snapshot Written by ADExp.exe or ADExplorer.exe
Windows: Sysinternals ADExplorer invoked with snapshot flag to create AD database snapshot
Windows PowerShell module commandlet names matching known exploitation and post-exploitation tooling
Windows Process Creation: Suspicious PowerShell Commandlets Used by Known Exploitation Tools
Windows Process Creation: Renamed AdFind.exe Executions
Windows file creation for SharpHound/BloodHound collection output filenames
Windows LDAP Client Event ID 30 Active Directory enumeration via LDAP search filters
Windows Process Creation: AdFind Executed with Suspicious Recon Flags
Windows Process Execution of Bloodhound/SharpHound Command-Line Collection Options
Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database
Pivot detection · T1069.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.