Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database
Flags Sysinternals ADExplorer running with -snapshot to export an Active Directory database to suspicious local directories.
- Product
- windows
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-03-14
- Updated
- 2026-07-30
ATT&CK techniques
DiscoveryRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies execution of Sysinternals ADExplorer binaries when the command line includes the -snapshot flag and the snapshot output path is consistent with commonly abused writable locations. Saving a local copy of the Active Directory database can enable directory data discovery and downstream attacks such as credential-focused workflows (without requiring password hash extraction). Telemetry relies on Windows process creation events including Image/OriginalFileName, Product metadata, and full command-line and path content.
Reporting behind it
- documentcloud.orghttps://www.documentcloud.org/documents/5743766-Global-Threat-Report-2019.html
- learn.microsoft.comhttps://learn.microsoft.com/de-de/sysinternals/downloads/adexplorer
- github.comhttps://github.com/c3c/ADExplorerSnapshot.py/tree/f700904defac330802bbfedd1d8ffd9248f4ee24
- packetlabs.nethttps://www.packetlabs.net/posts/scattered-spider-is-a-young-ransomware-gang-exploiting-large-corporations/
- nccgroup.comhttps://www.nccgroup.com/us/research-blog/lapsus-recent-techniques-tactics-and-procedures/
- trustedsec.comhttps://trustedsec.com/blog/adexplorer-on-engagements
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_sysinternals_adexplorer_susp_execution.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database"
id: 75bbe460-71ef-4532-9eb5-a1040e24cd2d
related:
- id: 9212f354-7775-4e28-9c9f-8f0a4544e664
type: derived
- id: ef61af62-bc74-4f58-b49b-626448227652
type: derived
status: test
description: This rule identifies execution of Sysinternals ADExplorer binaries when the command line includes the -snapshot flag and the snapshot output path is consistent with commonly abused writable locations. Saving a local copy of the Active Directory database can enable directory data discovery and downstream attacks such as credential-focused workflows (without requiring password hash extraction). Telemetry relies on Windows process creation events including Image/OriginalFileName, Product metadata, and full command-line and path content.
references:
- https://www.documentcloud.org/documents/5743766-Global-Threat-Report-2019.html
- https://learn.microsoft.com/de-de/sysinternals/downloads/adexplorer
- https://github.com/c3c/ADExplorerSnapshot.py/tree/f700904defac330802bbfedd1d8ffd9248f4ee24
- https://www.packetlabs.net/posts/scattered-spider-is-a-young-ransomware-gang-exploiting-large-corporations/
- https://www.nccgroup.com/us/research-blog/lapsus-recent-techniques-tactics-and-procedures/
- https://trustedsec.com/blog/adexplorer-on-engagements
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_sysinternals_adexplorer_susp_execution.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-03-14
modified: 2025-07-09
tags:
- attack.discovery
- attack.t1087.002
- attack.t1069.002
- attack.t1482
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith:
- \ADExp.exe
- \ADExplorer.exe
- \ADExplorer64.exe
- \ADExplorer64a.exe
- OriginalFileName: AdExp
- Description: Active Directory Editor
- Product: Sysinternals ADExplorer
selection_flag:
CommandLine|contains: snapshot
selection_paths:
CommandLine|contains:
- \Downloads\
- \Users\Public\
- \AppData\
- \Windows\Temp\
condition: all of selection_*
falsepositives:
- Unknown
level: high
license: DRL-1.1