Check out the results from our first round of ATT&CK Evaluations at attackevals.mitre.org!

dsquery

dsquery is a command-line utility that can be used to query Active Directory for information from a system within a domain. [1] It is typically installed only on Windows Server versions but can be installed on non-server variants through the Microsoft-provided Remote Server Administration Tools bundle.

ID: S0105
Aliases: dsquery, dsquery.exe
Type: TOOL
Platforms: Windows

Version: 1.0

Techniques Used

DomainIDNameUse
EnterpriseT1087Account Discoverydsquery can be used to gather information on user accounts within a domain.[1]
EnterpriseT1069Permission Groups Discoverydsquery can be used to gather information on permission groups within a domain.[1]

Groups

Groups that use this software:

FIN8

References