I have uploaded the new versions of AdFind and AdMod to www.joeware.net for download.
Note that I know that a lot of anti-malware has been reporting AdFind.exe as malware now, usually some form of LOLBIN or PUA. The reason for this is because the hacker collectives are using the tool for scanning Active Directory environments as part of ransomware attacks. There is nothing inherently dangerous with AdFind, it is just fast and useful so hackers are like we should use this because it is so good.
I have seen an article that said AdFind is deploying malware. That is absolutely incorrect, AdFind has no capability to deploy or change anything. It is purely an LDAP query tool. It submits LDAP queries and outputs the responses from LDAP Servers.
joe
EDIT: Updated malware to be anti-malware. I had a Freudian slip because I consider AV and anti-malware software to be some of the most evil malware.
“a lot of malware” ?!? Did you mean “a lots fo anti-malware”
Yes, it was a Freudian slip. 😀
Sadly Defender removed Adfind that I was using. Our ‘Security’ team did not accept my explanation.
Back to ADSISearcher.
That sucks David. Perhaps you can talk to your management chain about how long it takes to do things one way versus the other and explain that AdFind is only being blocked because of being a PuP/PuA/LOLBIN and that it can’t actually hurt anything since it is read only.