PowerShell Suspicious Discovery of Local Groups via Get-LocalGroup Cmdlets
Flags PowerShell commands that enumerate local groups and group membership, including WMI/CIM queries for Win32 group data.
- Product
- windows
- Category
- ps_script
- Author
- frack113 (SigmaHQ), DRL 1.1
- Published
- 2021-12-12
- Updated
- 2026-07-31
ATT&CK techniques
DiscoveryRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags PowerShell script block activity used to enumerate local groups and their members by matching calls to get-localgroup and get-localgroupmember. It matters because attackers often perform local permission discovery to identify which built-in groups exist and which accounts belong to them. The detection relies on Script Block Logging telemetry containing the executed PowerShell commands.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: PowerShell Suspicious Discovery of Local Groups via Get-LocalGroup Cmdlets
id: 2636e1fc-f5e5-4964-93ae-b24a1c630049
related:
- id: cef24b90-dddc-4ae1-a09a-8764872f69fc
type: similar
- id: fa6a5a45-3ee2-4529-aa14-ee5edc9e29cb
type: derived
status: test
description: This rule flags PowerShell script block activity used to enumerate local groups and their members by matching calls to get-localgroup and get-localgroupmember. It matters because attackers often perform local permission discovery to identify which built-in groups exist and which accounts belong to them. The detection relies on Script Block Logging telemetry containing the executed PowerShell commands.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.001/T1069.001.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_susp_local_group_reco.yml
author: frack113, Huntrule Team
date: 2021-12-12
modified: 2025-08-22
tags:
- attack.discovery
- attack.t1069.001
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection_localgroup:
ScriptBlockText|contains:
- "get-localgroup "
- "get-localgroupmember "
selection_wmi_module:
ScriptBlockText|contains:
- "get-wmiobject "
- "gwmi "
- "get-ciminstance "
- "gcim "
selection_wmi_class:
ScriptBlockText|contains: win32_group
condition: selection_localgroup or all of selection_wmi_*
falsepositives:
- Inventory scripts or admin tasks
level: low
license: DRL-1.1