Windows PowerShell AD Module DLL Import for Active Directory Enumeration

Flags PowerShell importing Microsoft.ActiveDirectory.Management.dll via Import-Module, a common step in AD discovery and enumeration.

FreeReviewedSigma · Medium · v2
Product
windows
Category
ps_module
Author
Nasreddine Bencherchali (Nextron Systems), frack113 (SigmaHQ), DRL 1.1
Published
2023-01-22
Updated
2026-07-31
title: Windows PowerShell AD Module DLL Import for Active Directory Enumeration
id: 461eeb5e-54ef-4cb6-b64c-2312182880bf
related:
  - id: 70bc5215-526f-4477-963c-a47a5c9ebd12
    type: similar
  - id: 9e620995-f2d8-4630-8430-4afd89f77604
    type: similar
  - id: 74176142-4684-4d8a-8b0a-713257e7df8e
    type: derived
status: test
description: This rule flags PowerShell activity that imports the Microsoft.ActiveDirectory.Management.dll using Import-Module (or its ipmo alias). Loading this AD management DLL is commonly used to query Active Directory for discovery and enumeration. It relies on PowerShell module import telemetry captured in command payloads and can be used to identify recon-like attempts that leverage the AD module library.
references:
  - https://github.com/samratashok/ADModule
  - https://twitter.com/cyb3rops/status/1617108657166061568?s=20
  - https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/active-directory-enumeration-with-ad-module-without-rsat-or-admin-privileges
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_module/posh_pm_active_directory_module_dll_import.yml
author: Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule Team
date: 2023-01-22
tags:
  - attack.reconnaissance
  - attack.discovery
  - attack.impact
logsource:
  product: windows
  category: ps_module
  definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
detection:
  selection_cmdlet:
    Payload|contains:
      - "Import-Module "
      - "ipmo "
  selection_dll:
    Payload|contains: Microsoft.ActiveDirectory.Management.dll
  condition: all of selection_*
falsepositives:
  - Legitimate use of the library for administrative activity
level: medium
license: DRL-1.1