| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1482 | 域信任发现 |
AdFind can gather information about organizational units (OUs) and domain trusts from Active Directory.[1][2][3][4] |
|
| Enterprise | T1069 | .002 | 权限组发现: Domain Groups | |
| Enterprise | T1016 | 系统网络配置发现 |
AdFind can extract subnet information from Active Directory.[1][2][3] |
|
| Enterprise | T1087 | .002 | 账号发现: Domain Account | |
| Enterprise | T1018 | 远程系统发现 |
AdFind has the ability to query Active Directory for computers.[1][2][3][5] |
|
| ID | Name | References |
|---|---|---|
| G0092 | TA505 | |
| G0102 | Wizard Spider | |
| G0046 | FIN7 | |
| G1040 | Play | |
| G0037 | FIN6 | |
| G1024 | Akira | |
| G1032 | INC Ransom | |
| G0016 | APT29 | |
| G0045 | menuPass |