Windows PowerShell Script Block Logging: AADInternals Cmdlets (Add-AADInt to Update-AADInt) Execution

Flags PowerShell script block execution that contains AADInternals cmdlet names (AADInt), indicating potential admin or abuse activity.

FreeReviewedSigma · High · v2
Product
windows
Category
ps_script
Author
Austin Songer (@austinsonger), Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-12-23
Updated
2026-07-31

What it detects

This rule identifies PowerShell script blocks that invoke AADInternals cmdlets by matching specific “-AADInt” command names such as Add-AADInt, Get-AADInt, Export-AADInt, Invoke-AADInt, and Update-AADInt. Such activity matters because AADInternals is an administration tool for Azure AD and Office 365 and its use in automated scripts can support malicious reconnaissance, credential access, or impact. Telemetry required is Script Block Logging with captured PowerShell ScriptBlockText content.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.