PowerShell discovery of local groups via Get-LocalGroup and Get-LocalGroupMember
Identifies PowerShell commands enumerating local groups and their members, indicating potential local permission discovery.
FreeUnreviewedSigmalowv1
powershell-discovery-of-local-groups-via-get-localgroup-and-get-localgroupmember-cef24b90
title: PowerShell discovery of local groups via Get-LocalGroup and Get-LocalGroupMember
id: ce90a52f-135a-4e0d-8103-a140fad7c2f3
related:
- id: fa6a5a45-3ee2-4529-aa14-ee5edc9e29cb
type: similar
- id: cef24b90-dddc-4ae1-a09a-8764872f69fc
type: derived
status: test
description: This rule flags PowerShell usage that retrieves local group and local group membership information using Get-LocalGroup and Get-LocalGroupMember. It can indicate attacker-led discovery to identify which local groups exist and which users belong to a target group, such as local administrators. Telemetry relies on PowerShell module/cmdlet command content in Payload and ContextInfo, including optional WMI-based enumeration patterns.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.001/T1069.001.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_module/posh_pm_susp_local_group_reco.yml
author: frack113, Huntrule Team
date: 2021-12-12
modified: 2025-08-22
tags:
- attack.discovery
- attack.t1069.001
logsource:
product: windows
category: ps_module
definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
detection:
selection_localgroup:
- Payload|contains:
- "get-localgroup "
- "get-localgroupmember "
- ContextInfo|contains:
- "get-localgroup "
- "get-localgroupmember "
selection_wmi_module:
- Payload|contains:
- "get-wmiobject "
- "gwmi "
- "get-ciminstance "
- "gcim "
- ContextInfo|contains|all:
- "get-wmiobject "
- "gwmi "
- "get-ciminstance "
- "gcim "
selection_wmi_class:
- Payload|contains: win32_group
- ContextInfo|contains: win32_group
condition: selection_localgroup or all of selection_wmi_*
falsepositives:
- Administrator script
level: low
license: DRL-1.1
What it detects
This rule flags PowerShell usage that retrieves local group and local group membership information using Get-LocalGroup and Get-LocalGroupMember. It can indicate attacker-led discovery to identify which local groups exist and which users belong to a target group, such as local administrators. Telemetry relies on PowerShell module/cmdlet command content in Payload and ContextInfo, including optional WMI-based enumeration patterns.
Known false positives
- Administrator script
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.