Ransomware Series: Active Directory & Network Discovery via AdFind/BloodHound-Style Enumeration
Detects the execution of common enumeration tools and commands often associated with ransomware-precursor behavior. This includes the use of AdFind, dsquery, net.exe, and nltest for domain account, group, and trust discovery, as well as the execution of BloodHound/SharpHound collection activities.
Microsoft Sentinel (KQL)

