PowerShell Password Policy Discovery via Get-AdDefaultDomainPasswordPolicy (Windows)

Alerts when PowerShell calls Get-AdDefaultDomainPasswordPolicy to enumerate an AD domain’s default password policy.

FreeReviewedSigma · Low · v2
Product
windows
Category
ps_script
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-03-17
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

Identifies PowerShell script block activity that calls Get-AdDefaultDomainPasswordPolicy to retrieve the default password policy for an Active Directory domain. Attackers can use this information to understand password complexity and other authentication requirements before attempting credential attacks. The rule relies on Script Block Logging telemetry that includes the executed PowerShell code text.

Related detections6 linkedT1201 — drag to rearrange
Suspicious Secedit Security Policy Export for Reconnaissance (via process_creation)
Windows Security Event 4661 Password Policy Enumeration via ReadPasswordParameters
Windows process creation: CrackMapExec execution via characteristic command-line flags
Linux Password Policy Discovery via chage and passwd Commands
Cisco AAA discovery via show/dir commands
Windows Process Creation: Execution of Net.exe or Net1.exe
PowerShell Password Policy Discovery via Get-AdDefaultDomainPasswordPolicy (Windows)
Pivot detection · T1201 · 6 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.