dsquery is a Windows/Active Directory command-line utility used for domain discovery. The provided content specifically describes its use to gather information on user accounts within a domain and to gather information on permission groups within a domain. It is referenced in ATT&CK-style reporting as being used during account and group enumeration in AD environments, including in Operation CuckooBees where threat actors used dsquery together with dsget to obtain domain environment information and query users in administrative groups. High-confidence behavior from the content is limited to AD/domain reconnaissance and enumeration of domain users and groups; no additional malware-specific infection vector, persistence, or payload behavior is described.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
BoomBox has the ability to execute an LDAP query to enumerate the distinguished name, SAM account name, and display name for all domain users. IceApple Active Directory Querier module can perform authenticated requests against an Active Directory server. Sandworm Team has used a tool to query Active Directory using LDAP.
The content notes that querying different domain controllers can reveal last login information and discusses identifying users tied to systems and groups.
The article shows queries for groups with *admin* in the name, listing members of Domain Admins, and using the memberof attribute to find users in one or multiple groups.
Multiple tools/actors are described using Active Directory/domain group enumeration, e.g., “AdFind can enumerate domain groups”, “net group "domain admins" /domain to enumerate domain groups”, “BloodHound can collect information about domain groups and members”, and “AD Explorer tool to enumerate groups on a victim's network.”
For computer enumeration, the author recommends adding the operatingsystem attribute to output or filters because it provides useful information when choosing systems to target.
Examples include enumerating all users, searching for likely privileged accounts by naming convention, checking group membership, and identifying accounts with old pwdLastSet values.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows administrative utility used to query and gather domain user account information.
Windows directory service query utility used to enumerate AD objects such as groups for reconnaissance.
Built-in Windows/AD command-line utility used to query directory objects, including domain user accounts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.