PowerShell discovery of local groups via Get-LocalGroup and Get-LocalGroupMember

Identifies PowerShell commands enumerating local groups and their members, indicating potential local permission discovery.

FreeUnreviewedSigmalowv1
title: PowerShell discovery of local groups via Get-LocalGroup and Get-LocalGroupMember
id: ce90a52f-135a-4e0d-8103-a140fad7c2f3
related:
  - id: fa6a5a45-3ee2-4529-aa14-ee5edc9e29cb
    type: similar
  - id: cef24b90-dddc-4ae1-a09a-8764872f69fc
    type: derived
status: test
description: This rule flags PowerShell usage that retrieves local group and local group membership information using Get-LocalGroup and Get-LocalGroupMember. It can indicate attacker-led discovery to identify which local groups exist and which users belong to a target group, such as local administrators. Telemetry relies on PowerShell module/cmdlet command content in Payload and ContextInfo, including optional WMI-based enumeration patterns.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.001/T1069.001.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_module/posh_pm_susp_local_group_reco.yml
author: frack113, Huntrule Team
date: 2021-12-12
modified: 2025-08-22
tags:
  - attack.discovery
  - attack.t1069.001
logsource:
  product: windows
  category: ps_module
  definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
detection:
  selection_localgroup:
    - Payload|contains:
        - "get-localgroup "
        - "get-localgroupmember "
    - ContextInfo|contains:
        - "get-localgroup "
        - "get-localgroupmember "
  selection_wmi_module:
    - Payload|contains:
        - "get-wmiobject "
        - "gwmi "
        - "get-ciminstance "
        - "gcim "
    - ContextInfo|contains|all:
        - "get-wmiobject "
        - "gwmi "
        - "get-ciminstance "
        - "gcim "
  selection_wmi_class:
    - Payload|contains: win32_group
    - ContextInfo|contains: win32_group
  condition: selection_localgroup or all of selection_wmi_*
falsepositives:
  - Administrator script
level: low
license: DRL-1.1

What it detects

This rule flags PowerShell usage that retrieves local group and local group membership information using Get-LocalGroup and Get-LocalGroupMember. It can indicate attacker-led discovery to identify which local groups exist and which users belong to a target group, such as local administrators. Telemetry relies on PowerShell module/cmdlet command content in Payload and ContextInfo, including optional WMI-based enumeration patterns.

Known false positives

  • Administrator script

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.