Windows PowerShell AD Module DLL Import for Active Directory Enumeration
Flags PowerShell importing Microsoft.ActiveDirectory.Management.dll via Import-Module, a common step in AD discovery and enumeration.
FreeReviewedSigma · Medium · v2
- Product
- windows
- Category
- ps_module
- Author
- Nasreddine Bencherchali (Nextron Systems), frack113 (SigmaHQ), DRL 1.1
- Published
- 2023-01-22
- Updated
- 2026-07-31
What it detects
This rule flags PowerShell activity that imports the Microsoft.ActiveDirectory.Management.dll using Import-Module (or its ipmo alias). Loading this AD management DLL is commonly used to query Active Directory for discovery and enumeration. It relies on PowerShell module import telemetry captured in command payloads and can be used to identify recon-like attempts that leverage the AD module library.
Reporting behind it
- github.comhttps://github.com/samratashok/ADModule
- twitter.comhttps://twitter.com/cyb3rops/status/1617108657166061568?s=20
- ired.teamhttps://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/active-directory-enumeration-with-ad-module-without-rsat-or-admin-privileges
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_module/posh_pm_active_directory_module_dll_import.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
windows-powershell-active-directory-module-load-via-import-module-74176142
title: Windows PowerShell AD Module DLL Import for Active Directory Enumeration
id: 461eeb5e-54ef-4cb6-b64c-2312182880bf
related:
- id: 70bc5215-526f-4477-963c-a47a5c9ebd12
type: similar
- id: 9e620995-f2d8-4630-8430-4afd89f77604
type: similar
- id: 74176142-4684-4d8a-8b0a-713257e7df8e
type: derived
status: test
description: This rule flags PowerShell activity that imports the Microsoft.ActiveDirectory.Management.dll using Import-Module (or its ipmo alias). Loading this AD management DLL is commonly used to query Active Directory for discovery and enumeration. It relies on PowerShell module import telemetry captured in command payloads and can be used to identify recon-like attempts that leverage the AD module library.
references:
- https://github.com/samratashok/ADModule
- https://twitter.com/cyb3rops/status/1617108657166061568?s=20
- https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/active-directory-enumeration-with-ad-module-without-rsat-or-admin-privileges
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_module/posh_pm_active_directory_module_dll_import.yml
author: Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule Team
date: 2023-01-22
tags:
- attack.reconnaissance
- attack.discovery
- attack.impact
logsource:
product: windows
category: ps_module
definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
detection:
selection_cmdlet:
Payload|contains:
- "Import-Module "
- "ipmo "
selection_dll:
Payload|contains: Microsoft.ActiveDirectory.Management.dll
condition: all of selection_*
falsepositives:
- Legitimate use of the library for administrative activity
level: medium
license: DRL-1.1