Windows PowerShell Execution of AADInternals Cmdlets (process creation)

Flags PowerShell processes running AADInternals “-AADInt” cmdlets, indicating potential Azure AD/Office 365 administration or abuse.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Austin Songer (@austinsonger), Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-12-23
Updated
2026-07-30

What it detects

This rule identifies Windows process creation events where PowerShell is launched and the command line includes AADInternals cmdlets (e.g., Add-AADInt, Get-AADInt, Invoke-AADInt). Attackers can abuse AADInternals to administer or interact with Azure AD and Office 365, making these cmdlet invocations a useful signal for suspicious automation and recon. It relies on telemetry that records the created process image (powershell.exe/pwsh.exe) and the full command line content.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.