Windows PowerShell ScriptBlock: Get-ADComputer reconnaissance for unconstrained delegation properties

Flags PowerShell script blocks that query AD computer delegation-related properties using Get-ADComputer-style discovery.

FreeReviewedSigma · Medium · v2
Product
windows
Category
ps_script
Author
frack113 (SigmaHQ), DRL 1.1
Published
2025-03-05
Updated
2026-07-31

ATT&CK techniques

Recon → Discovery
  1. Resource Dev

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags PowerShell ScriptBlock content that uses Get-ADComputer-related property lookups aimed at finding systems configured for unconstrained delegation. Attackers can use this information to identify high-value targets for subsequent credential theft and lateral movement. It relies on Script Block Logging telemetry by matching specific AD property and LDAP filter patterns related to delegation settings.

Related detections9 linkedT1018 — drag to rearrange
Suspicious Domain Controller Enumeration via Nltest by DeadLock Ransomware
Malicious Kerberos proxiable/S4U2self Ticket - CVE-2021-42278/42287 (via security)
Malicious Rubeus Kerberos Unconstrained Delegation Abuse (via security)
Malicious Rubeus Kerberos Constrained Delegation Abuse - S4U2Proxy (via security)
Renamed Mimikatz Credential Theft Command Indicators (via process_creation)
Malicious DNS Hosts File Accessed via Network Share (via security)
Suspicious Active Directory Subnet Enumeration via ADFind Subnets Query (via process_creation)
Suspicious Remote Connection to ADWS Port 9389 via security
Uncommon Domain Trust Discovery via Nltest (via process_creation)
Windows PowerShell ScriptBlock: Get-ADComputer reconnaissance for unconstrained delegation properties
Pivot detection · T1018 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.