Suspicious PowerShell Execution of DSInternals Cmdlets on Windows
Flags PowerShell command lines invoking specific DSInternals cmdlets that can support AD/credential and key material operations.
FreeUnreviewedSigmahighv1
suspicious-powershell-execution-of-dsinternals-cmdlets-on-windows-43d91656
title: Suspicious PowerShell Execution of DSInternals Cmdlets on Windows
id: 7d77fb0d-8f81-4dc2-8c9b-68bc2296729d
related:
- id: 846c7a87-8e14-4569-9d49-ecfd4276a01c
type: similar
- id: 43d91656-a9b2-4541-b7e2-6a9bd3a13f4e
type: derived
status: test
description: This rule identifies Windows process executions where the PowerShell command line contains DSInternals module cmdlets related to Active Directory and related credential/key operations. An attacker may use these cmdlets to enumerate domain objects and keys, transform password material, or interact with stored backup/NTDS artifacts that can support credential access or directory manipulation. Telemetry relies on process creation events with a captured command line that includes the specified DSInternals function names.
references:
- https://github.com/MichaelGrafnetter/DSInternals/blob/39ee8a69bbdc1cfd12c9afdd7513b4788c4895d4/Src/DSInternals.PowerShell/DSInternals.psd1
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_dsinternals_cmdlets.yml
author: Nasreddine Bencherchali (Nextron Systems), Nounou Mbeiri, Huntrule Team
date: 2024-06-26
tags:
- attack.execution
- attack.t1059.001
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains:
- Add-ADDBSidHistory
- Add-ADNgcKey
- Add-ADReplNgcKey
- ConvertFrom-ADManagedPasswordBlob
- ConvertFrom-GPPrefPassword
- ConvertFrom-ManagedPasswordBlob
- ConvertFrom-UnattendXmlPassword
- ConvertFrom-UnicodePassword
- ConvertTo-AADHash
- ConvertTo-GPPrefPassword
- ConvertTo-KerberosKey
- ConvertTo-LMHash
- ConvertTo-MsoPasswordHash
- ConvertTo-NTHash
- ConvertTo-OrgIdHash
- ConvertTo-UnicodePassword
- Disable-ADDBAccount
- Enable-ADDBAccount
- Get-ADDBAccount
- Get-ADDBBackupKey
- Get-ADDBDomainController
- Get-ADDBGroupManagedServiceAccount
- Get-ADDBKdsRootKey
- Get-ADDBSchemaAttribute
- Get-ADDBServiceAccount
- Get-ADDefaultPasswordPolicy
- Get-ADKeyCredential
- Get-ADPasswordPolicy
- Get-ADReplAccount
- Get-ADReplBackupKey
- Get-ADReplicationAccount
- Get-ADSIAccount
- Get-AzureADUserEx
- Get-BootKey
- Get-KeyCredential
- Get-LsaBackupKey
- Get-LsaPolicy
- Get-SamPasswordPolicy
- Get-SysKey
- Get-SystemKey
- New-ADDBRestoreFromMediaScript
- New-ADKeyCredential
- New-ADNgcKey
- New-NTHashSet
- Remove-ADDBObject
- Save-DPAPIBlob
- Set-ADAccountPasswordHash
- Set-ADDBAccountPassword
- Set-ADDBBootKey
- Set-ADDBDomainController
- Set-ADDBPrimaryGroup
- Set-ADDBSysKey
- Set-AzureADUserEx
- Set-LsaPolicy
- Set-SamAccountPasswordHash
- Set-WinUserPasswordHash
- Test-ADDBPasswordQuality
- Test-ADPasswordQuality
- Test-ADReplPasswordQuality
- Test-PasswordQuality
- Unlock-ADDBAccount
- Write-ADNgcKey
- Write-ADReplNgcKey
condition: selection
falsepositives:
- Legitimate usage of DSInternals for administration or audit purpose.
level: high
license: DRL-1.1
What it detects
This rule identifies Windows process executions where the PowerShell command line contains DSInternals module cmdlets related to Active Directory and related credential/key operations. An attacker may use these cmdlets to enumerate domain objects and keys, transform password material, or interact with stored backup/NTDS artifacts that can support credential access or directory manipulation. Telemetry relies on process creation events with a captured command line that includes the specified DSInternals function names.
Known false positives
- Legitimate usage of DSInternals for administration or audit purpose.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.