AD service/MySQL credential and computer object recon via LOTL tooling
Detects the execution of common system administration tools (cmd, powershell, net, nltest, etc.) used to perform environment discovery or credential enumeration, specifically when targeting Domain Controllers, Active Directory objects, database credentials, or sensitive configuration files.
Microsoft Sentinel (KQL)

