ADFind or dsquery LDAP Domain Account Enumeration (T1087.002)

Detects the execution of known Active Directory discovery tools, specifically 'adfind.exe' or 'dsquery.exe' with arguments targeting user or group enumeration. These tools are commonly used by adversaries during the reconnaissance phase to map domain structure.