PowerShell: Active Directory computer enumeration via Get-AdComputer

Flags PowerShell script blocks using Get-ADComputer with enumeration-related parameters for AD computer discovery.

FreeReviewedSigma · Low · v2
Product
windows
Category
ps_script
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-03-17
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies PowerShell script block content that includes the Get-AdComputer cmdlet followed by common parameters used to enumerate Active Directory computer objects or request their properties. Enumeration helps attackers discover targets, naming patterns, and system attributes for follow-on activity. It relies on Script Block Logging telemetry capturing the executed PowerShell text and parameters.

Related detections9 linkedT1087.002 — drag to rearrange
Suspicious Remote Connection to ADWS Port 9389 via security
Suspicious AdFind Active Directory Reconnaissance Tool Execution (via process_creation)
Suspicious Active Directory Enumeration via ADWS PowerShell Cmdlets via ps_script
Windows Process Creation: Renamed AdFind.exe Executions
Windows Process Creation: AdFind Executed with Suspicious Recon Flags
Windows Process Creation: Execution of Net.exe or Net1.exe
Suspicious Active Directory Reconnaissance via ADExplorer or ADRecon (via process_creation)
Suspicious Service Principal Name Enumeration via Setspn by UAT-8837
Suspicious Domain Controller Enumeration via Nltest by DeadLock Ransomware
PowerShell: Active Directory computer enumeration via Get-AdComputer
Pivot detection · T1087.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.