Windows ADExplorer AD Snapshot File Written

Last updated on:

In this page

About the rule

Rule Type

Standard

Rule Description

Detects ADExplorer Active Directory snapshot files, which may be abused to extract data for BloodHound, password spraying, or social engineering.

Severity

Trouble

Detection

Execution Mode

realtime

Log Sources

Windows

Author

@Arnim Rupp (Nextron Systems), Thomas Patzke