Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database

Flags Sysinternals ADExplorer running with -snapshot to export an Active Directory database to suspicious local directories.

FreeUnreviewedSigmahighv1
title: "Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database"
id: 75bbe460-71ef-4532-9eb5-a1040e24cd2d
related:
  - id: 9212f354-7775-4e28-9c9f-8f0a4544e664
    type: derived
  - id: ef61af62-bc74-4f58-b49b-626448227652
    type: derived
status: test
description: This rule identifies execution of Sysinternals ADExplorer binaries when the command line includes the -snapshot flag and the snapshot output path is consistent with commonly abused writable locations. Saving a local copy of the Active Directory database can enable directory data discovery and downstream attacks such as credential-focused workflows (without requiring password hash extraction). Telemetry relies on Windows process creation events including Image/OriginalFileName, Product metadata, and full command-line and path content.
references:
  - https://www.documentcloud.org/documents/5743766-Global-Threat-Report-2019.html
  - https://learn.microsoft.com/de-de/sysinternals/downloads/adexplorer
  - https://github.com/c3c/ADExplorerSnapshot.py/tree/f700904defac330802bbfedd1d8ffd9248f4ee24
  - https://www.packetlabs.net/posts/scattered-spider-is-a-young-ransomware-gang-exploiting-large-corporations/
  - https://www.nccgroup.com/us/research-blog/lapsus-recent-techniques-tactics-and-procedures/
  - https://trustedsec.com/blog/adexplorer-on-engagements
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_sysinternals_adexplorer_susp_execution.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-03-14
modified: 2025-07-09
tags:
  - attack.discovery
  - attack.t1087.002
  - attack.t1069.002
  - attack.t1482
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith:
        - \ADExp.exe
        - \ADExplorer.exe
        - \ADExplorer64.exe
        - \ADExplorer64a.exe
    - OriginalFileName: AdExp
    - Description: Active Directory Editor
    - Product: Sysinternals ADExplorer
  selection_flag:
    CommandLine|contains: snapshot
  selection_paths:
    CommandLine|contains:
      - \Downloads\
      - \Users\Public\
      - \AppData\
      - \Windows\Temp\
  condition: all of selection_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule identifies execution of Sysinternals ADExplorer binaries when the command line includes the -snapshot flag and the snapshot output path is consistent with commonly abused writable locations. Saving a local copy of the Active Directory database can enable directory data discovery and downstream attacks such as credential-focused workflows (without requiring password hash extraction). Telemetry relies on Windows process creation events including Image/OriginalFileName, Product metadata, and full command-line and path content.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.