PowerShell Local Group Discovery via Get-LocalGroup and Get-LocalGroupMember (Windows)
Identifies PowerShell commands enumerating local groups and their members, indicating potential local permission discovery.
- Product
- windows
- Category
- ps_module
- Author
- frack113 (SigmaHQ), DRL 1.1
- Published
- 2021-12-12
- Updated
- 2026-07-31
ATT&CK techniques
DiscoveryRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies PowerShell activity that queries local group names and group membership using Get-LocalGroup and Get-LocalGroupMember, including similar WMI-based group enumeration. Such discovery helps an attacker understand local permissions and identify which users belong to privileged local groups. It relies on telemetry containing the command text in PowerShell module/cmdlet execution fields (Payload and ContextInfo), including WMI calls that reference the Win32_Group class.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: PowerShell Local Group Discovery via Get-LocalGroup and Get-LocalGroupMember (Windows)
id: ce90a52f-135a-4e0d-8103-a140fad7c2f3
related:
- id: fa6a5a45-3ee2-4529-aa14-ee5edc9e29cb
type: similar
- id: cef24b90-dddc-4ae1-a09a-8764872f69fc
type: derived
status: test
description: This rule identifies PowerShell activity that queries local group names and group membership using Get-LocalGroup and Get-LocalGroupMember, including similar WMI-based group enumeration. Such discovery helps an attacker understand local permissions and identify which users belong to privileged local groups. It relies on telemetry containing the command text in PowerShell module/cmdlet execution fields (Payload and ContextInfo), including WMI calls that reference the Win32_Group class.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.001/T1069.001.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_module/posh_pm_susp_local_group_reco.yml
author: frack113, Huntrule Team
date: 2021-12-12
modified: 2025-08-22
tags:
- attack.discovery
- attack.t1069.001
logsource:
product: windows
category: ps_module
definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
detection:
selection_localgroup:
- Payload|contains:
- "get-localgroup "
- "get-localgroupmember "
- ContextInfo|contains:
- "get-localgroup "
- "get-localgroupmember "
selection_wmi_module:
- Payload|contains:
- "get-wmiobject "
- "gwmi "
- "get-ciminstance "
- "gcim "
- ContextInfo|contains|all:
- "get-wmiobject "
- "gwmi "
- "get-ciminstance "
- "gcim "
selection_wmi_class:
- Payload|contains: win32_group
- ContextInfo|contains: win32_group
condition: selection_localgroup or all of selection_wmi_*
falsepositives:
- Administrator script
level: low
license: DRL-1.1