Suspicious PowerShell Execution of DSInternals Cmdlets on Windows
Flags PowerShell command lines invoking specific DSInternals cmdlets that can support AD/credential and key material operations.
- Product
- windows
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems), Nounou Mbeiri (SigmaHQ), DRL 1.1
- Published
- 2024-06-26
- Updated
- 2026-07-30
ATT&CK techniques
ExecutionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies Windows process executions where the PowerShell command line contains DSInternals module cmdlets related to Active Directory and related credential/key operations. An attacker may use these cmdlets to enumerate domain objects and keys, transform password material, or interact with stored backup/NTDS artifacts that can support credential access or directory manipulation. Telemetry relies on process creation events with a captured command line that includes the specified DSInternals function names.
Reporting behind it
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Suspicious PowerShell Execution of DSInternals Cmdlets on Windows
id: 7d77fb0d-8f81-4dc2-8c9b-68bc2296729d
related:
- id: 846c7a87-8e14-4569-9d49-ecfd4276a01c
type: similar
- id: 43d91656-a9b2-4541-b7e2-6a9bd3a13f4e
type: derived
status: test
description: This rule identifies Windows process executions where the PowerShell command line contains DSInternals module cmdlets related to Active Directory and related credential/key operations. An attacker may use these cmdlets to enumerate domain objects and keys, transform password material, or interact with stored backup/NTDS artifacts that can support credential access or directory manipulation. Telemetry relies on process creation events with a captured command line that includes the specified DSInternals function names.
references:
- https://github.com/MichaelGrafnetter/DSInternals/blob/39ee8a69bbdc1cfd12c9afdd7513b4788c4895d4/Src/DSInternals.PowerShell/DSInternals.psd1
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_dsinternals_cmdlets.yml
author: Nasreddine Bencherchali (Nextron Systems), Nounou Mbeiri, Huntrule Team
date: 2024-06-26
tags:
- attack.execution
- attack.t1059.001
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains:
- Add-ADDBSidHistory
- Add-ADNgcKey
- Add-ADReplNgcKey
- ConvertFrom-ADManagedPasswordBlob
- ConvertFrom-GPPrefPassword
- ConvertFrom-ManagedPasswordBlob
- ConvertFrom-UnattendXmlPassword
- ConvertFrom-UnicodePassword
- ConvertTo-AADHash
- ConvertTo-GPPrefPassword
- ConvertTo-KerberosKey
- ConvertTo-LMHash
- ConvertTo-MsoPasswordHash
- ConvertTo-NTHash
- ConvertTo-OrgIdHash
- ConvertTo-UnicodePassword
- Disable-ADDBAccount
- Enable-ADDBAccount
- Get-ADDBAccount
- Get-ADDBBackupKey
- Get-ADDBDomainController
- Get-ADDBGroupManagedServiceAccount
- Get-ADDBKdsRootKey
- Get-ADDBSchemaAttribute
- Get-ADDBServiceAccount
- Get-ADDefaultPasswordPolicy
- Get-ADKeyCredential
- Get-ADPasswordPolicy
- Get-ADReplAccount
- Get-ADReplBackupKey
- Get-ADReplicationAccount
- Get-ADSIAccount
- Get-AzureADUserEx
- Get-BootKey
- Get-KeyCredential
- Get-LsaBackupKey
- Get-LsaPolicy
- Get-SamPasswordPolicy
- Get-SysKey
- Get-SystemKey
- New-ADDBRestoreFromMediaScript
- New-ADKeyCredential
- New-ADNgcKey
- New-NTHashSet
- Remove-ADDBObject
- Save-DPAPIBlob
- Set-ADAccountPasswordHash
- Set-ADDBAccountPassword
- Set-ADDBBootKey
- Set-ADDBDomainController
- Set-ADDBPrimaryGroup
- Set-ADDBSysKey
- Set-AzureADUserEx
- Set-LsaPolicy
- Set-SamAccountPasswordHash
- Set-WinUserPasswordHash
- Test-ADDBPasswordQuality
- Test-ADPasswordQuality
- Test-ADReplPasswordQuality
- Test-PasswordQuality
- Unlock-ADDBAccount
- Write-ADNgcKey
- Write-ADReplNgcKey
condition: selection
falsepositives:
- Legitimate usage of DSInternals for administration or audit purpose.
level: high
license: DRL-1.1