Renamed AdFind Execution — Detection Rule

Detects the use of a renamed Adfind.exe. AdFind continues to be seen across majority of breaches. It is used to domain trust discovery to plan out subsequent steps in the attack chain.

Read the full analysis on IntelFusions