Windows: Sysinternals ADExplorer invoked with snapshot flag to create AD database snapshot

Flags Sysinternals ADExplorer running with "snapshot" to create a local Active Directory database copy.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-03-14
Updated
2026-07-30

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies execution of Sysinternals ADExplorer when the command line includes the "snapshot" flag, indicating an attempt to save a local copy of the Active Directory database. Attackers may use this snapshot to extract data for analysis or enable subsequent credential and social engineering activities, even though password hashes are not included. It relies on Windows process creation telemetry and matches the executable identity (ADExplorer variants) plus the presence of the snapshot parameter in the command line.

Related detections9 linkedT1069.002 — drag to rearrange
Windows File Events: ADExplorer .dat Snapshot Written by ADExp.exe or ADExplorer.exe
Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database
Windows PowerShell module commandlet names matching known exploitation and post-exploitation tooling
Windows Process Creation: Suspicious PowerShell Commandlets Used by Known Exploitation Tools
Windows Process Creation: Renamed AdFind.exe Executions
Windows file creation for SharpHound/BloodHound collection output filenames
Windows LDAP Client Event ID 30 Active Directory enumeration via LDAP search filters
Windows Process Creation: AdFind Executed with Suspicious Recon Flags
Windows Process Execution of Bloodhound/SharpHound Command-Line Collection Options
Windows: Sysinternals ADExplorer invoked with snapshot flag to create AD database snapshot
Pivot detection · T1069.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.