| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1087 | .002 | Account Discovery: Domain Account | |
| Enterprise | T1482 | Domain Trust Discovery |
AdFind can gather information about organizational units (OUs) and domain trusts from Active Directory.[1][2][3][5] |
|
| Enterprise | T1069 | .002 | Permission Groups Discovery: Domain Groups | |
| Enterprise | T1018 | Remote System Discovery |
AdFind has the ability to query Active Directory for computers.[1][2][3][4] |
|
| Enterprise | T1016 | System Network Configuration Discovery |
AdFind can extract subnet information from Active Directory.[1][2][3] |
|
| ID | Name | References |
|---|---|---|
| G0092 | TA505 | |
| G0030 | Lotus Blossom |
Lotus Blossom has used AdFind to query Active Directory in victim environments.[7] |
| G0102 | Wizard Spider | |
| G0046 | FIN7 | |
| G1040 | Play | |
| G1043 | BlackByte | |
| G0037 | FIN6 | |
| G1024 | Akira | |
| G1032 | INC Ransom | |
| G0016 | APT29 | |
| G0045 | menuPass |