PowerShell Local Group Discovery via Get-LocalGroup and Get-LocalGroupMember (Windows)

Identifies PowerShell commands enumerating local groups and their members, indicating potential local permission discovery.

FreeReviewedSigma · Low · v2
Product
windows
Category
ps_module
Author
frack113 (SigmaHQ), DRL 1.1
Published
2021-12-12
Updated
2026-07-31
title: PowerShell Local Group Discovery via Get-LocalGroup and Get-LocalGroupMember (Windows)
id: ce90a52f-135a-4e0d-8103-a140fad7c2f3
related:
  - id: fa6a5a45-3ee2-4529-aa14-ee5edc9e29cb
    type: similar
  - id: cef24b90-dddc-4ae1-a09a-8764872f69fc
    type: derived
status: test
description: This rule identifies PowerShell activity that queries local group names and group membership using Get-LocalGroup and Get-LocalGroupMember, including similar WMI-based group enumeration. Such discovery helps an attacker understand local permissions and identify which users belong to privileged local groups. It relies on telemetry containing the command text in PowerShell module/cmdlet execution fields (Payload and ContextInfo), including WMI calls that reference the Win32_Group class.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.001/T1069.001.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_module/posh_pm_susp_local_group_reco.yml
author: frack113, Huntrule Team
date: 2021-12-12
modified: 2025-08-22
tags:
  - attack.discovery
  - attack.t1069.001
logsource:
  product: windows
  category: ps_module
  definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
detection:
  selection_localgroup:
    - Payload|contains:
        - "get-localgroup "
        - "get-localgroupmember "
    - ContextInfo|contains:
        - "get-localgroup "
        - "get-localgroupmember "
  selection_wmi_module:
    - Payload|contains:
        - "get-wmiobject "
        - "gwmi "
        - "get-ciminstance "
        - "gcim "
    - ContextInfo|contains|all:
        - "get-wmiobject "
        - "gwmi "
        - "get-ciminstance "
        - "gcim "
  selection_wmi_class:
    - Payload|contains: win32_group
    - ContextInfo|contains: win32_group
  condition: selection_localgroup or all of selection_wmi_*
falsepositives:
  - Administrator script
level: low
license: DRL-1.1