Suspicious PowerShell Execution of DSInternals Cmdlets on Windows

Flags PowerShell command lines invoking specific DSInternals cmdlets that can support AD/credential and key material operations.

FreeUnreviewedSigmahighv1
title: Suspicious PowerShell Execution of DSInternals Cmdlets on Windows
id: 7d77fb0d-8f81-4dc2-8c9b-68bc2296729d
related:
  - id: 846c7a87-8e14-4569-9d49-ecfd4276a01c
    type: similar
  - id: 43d91656-a9b2-4541-b7e2-6a9bd3a13f4e
    type: derived
status: test
description: This rule identifies Windows process executions where the PowerShell command line contains DSInternals module cmdlets related to Active Directory and related credential/key operations. An attacker may use these cmdlets to enumerate domain objects and keys, transform password material, or interact with stored backup/NTDS artifacts that can support credential access or directory manipulation. Telemetry relies on process creation events with a captured command line that includes the specified DSInternals function names.
references:
  - https://github.com/MichaelGrafnetter/DSInternals/blob/39ee8a69bbdc1cfd12c9afdd7513b4788c4895d4/Src/DSInternals.PowerShell/DSInternals.psd1
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_dsinternals_cmdlets.yml
author: Nasreddine Bencherchali (Nextron Systems), Nounou Mbeiri, Huntrule Team
date: 2024-06-26
tags:
  - attack.execution
  - attack.t1059.001
logsource:
  product: windows
  category: process_creation
detection:
  selection:
    CommandLine|contains:
      - Add-ADDBSidHistory
      - Add-ADNgcKey
      - Add-ADReplNgcKey
      - ConvertFrom-ADManagedPasswordBlob
      - ConvertFrom-GPPrefPassword
      - ConvertFrom-ManagedPasswordBlob
      - ConvertFrom-UnattendXmlPassword
      - ConvertFrom-UnicodePassword
      - ConvertTo-AADHash
      - ConvertTo-GPPrefPassword
      - ConvertTo-KerberosKey
      - ConvertTo-LMHash
      - ConvertTo-MsoPasswordHash
      - ConvertTo-NTHash
      - ConvertTo-OrgIdHash
      - ConvertTo-UnicodePassword
      - Disable-ADDBAccount
      - Enable-ADDBAccount
      - Get-ADDBAccount
      - Get-ADDBBackupKey
      - Get-ADDBDomainController
      - Get-ADDBGroupManagedServiceAccount
      - Get-ADDBKdsRootKey
      - Get-ADDBSchemaAttribute
      - Get-ADDBServiceAccount
      - Get-ADDefaultPasswordPolicy
      - Get-ADKeyCredential
      - Get-ADPasswordPolicy
      - Get-ADReplAccount
      - Get-ADReplBackupKey
      - Get-ADReplicationAccount
      - Get-ADSIAccount
      - Get-AzureADUserEx
      - Get-BootKey
      - Get-KeyCredential
      - Get-LsaBackupKey
      - Get-LsaPolicy
      - Get-SamPasswordPolicy
      - Get-SysKey
      - Get-SystemKey
      - New-ADDBRestoreFromMediaScript
      - New-ADKeyCredential
      - New-ADNgcKey
      - New-NTHashSet
      - Remove-ADDBObject
      - Save-DPAPIBlob
      - Set-ADAccountPasswordHash
      - Set-ADDBAccountPassword
      - Set-ADDBBootKey
      - Set-ADDBDomainController
      - Set-ADDBPrimaryGroup
      - Set-ADDBSysKey
      - Set-AzureADUserEx
      - Set-LsaPolicy
      - Set-SamAccountPasswordHash
      - Set-WinUserPasswordHash
      - Test-ADDBPasswordQuality
      - Test-ADPasswordQuality
      - Test-ADReplPasswordQuality
      - Test-PasswordQuality
      - Unlock-ADDBAccount
      - Write-ADNgcKey
      - Write-ADReplNgcKey
  condition: selection
falsepositives:
  - Legitimate usage of DSInternals for administration or audit purpose.
level: high
license: DRL-1.1

What it detects

This rule identifies Windows process executions where the PowerShell command line contains DSInternals module cmdlets related to Active Directory and related credential/key operations. An attacker may use these cmdlets to enumerate domain objects and keys, transform password material, or interact with stored backup/NTDS artifacts that can support credential access or directory manipulation. Telemetry relies on process creation events with a captured command line that includes the specified DSInternals function names.

Known false positives

  • Legitimate usage of DSInternals for administration or audit purpose.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.