Windows Process Creation: net.exe or PowerShell creating AD group "ESX Admins"

Alerts on net.exe or PowerShell attempts to create a domain group named "ESX Admins" via AD/command-line parameters.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
frack113 (SigmaHQ), DRL 1.1
Published
2024-07-29
Updated
2026-07-31

What it detects

This rule flags Windows process activity where net.exe is executed with parameters to add a domain group named "ESX Admins", or where PowerShell creates a new Active Directory group with the same name. Group names like "ESX Admins" can confer high privileges on domain-joined ESXi hypervisors, so such creation attempts may indicate credentialed privilege escalation or preparation for ESXi administrative access. It relies on process creation telemetry, including the process image/original filename and command-line arguments containing the required flags and group name.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.