PowerShell Suspicious Local Group Discovery via Get-LocalGroup and Get-LocalGroupMember
Flags PowerShell commands that enumerate local groups and group membership, including WMI/CIM queries for Win32 group data.
FreeUnreviewedSigmalowv1
powershell-suspicious-local-group-discovery-via-get-localgroup-and-get-localgrou-fa6a5a45
title: PowerShell Suspicious Local Group Discovery via Get-LocalGroup and Get-LocalGroupMember
id: 2636e1fc-f5e5-4964-93ae-b24a1c630049
related:
- id: cef24b90-dddc-4ae1-a09a-8764872f69fc
type: similar
- id: fa6a5a45-3ee2-4529-aa14-ee5edc9e29cb
type: derived
status: test
description: This rule flags PowerShell script block activity that queries local group information using Get-LocalGroup and Get-LocalGroupMember. It can also match attempts to enumerate group data through WMI/CIM calls that include Win32 group-related classes. Such discovery helps an attacker understand local permissions and identify which accounts belong to privileged groups, relying on Script Block Logging telemetry to capture the executed command text.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.001/T1069.001.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_susp_local_group_reco.yml
author: frack113, Huntrule Team
date: 2021-12-12
modified: 2025-08-22
tags:
- attack.discovery
- attack.t1069.001
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection_localgroup:
ScriptBlockText|contains:
- "get-localgroup "
- "get-localgroupmember "
selection_wmi_module:
ScriptBlockText|contains:
- "get-wmiobject "
- "gwmi "
- "get-ciminstance "
- "gcim "
selection_wmi_class:
ScriptBlockText|contains: win32_group
condition: selection_localgroup or all of selection_wmi_*
falsepositives:
- Inventory scripts or admin tasks
level: low
license: DRL-1.1
What it detects
This rule flags PowerShell script block activity that queries local group information using Get-LocalGroup and Get-LocalGroupMember. It can also match attempts to enumerate group data through WMI/CIM calls that include Win32 group-related classes. Such discovery helps an attacker understand local permissions and identify which accounts belong to privileged groups, relying on Script Block Logging telemetry to capture the executed command text.
Known false positives
- Inventory scripts or admin tasks
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.