This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Computer Discovery And Export Via Get-ADComputer Cmdlet - PowerShell
Original Source:
[Sigma source]
Title:
Computer Discovery And Export Via Get-ADComputer Cmdlet - PowerShell
Status:
test
Description:
Detects usage of the Get-ADComputer cmdlet to collect computer information and output it to a file
References:
-http://blog.talosintelligence.com/2022/09/lazarus-three-rats.html
-https://www.microsoft.com/en-us/security/blog/2022/10/18/defenders-beware-a-case-for-post-ransomware-investigations/
-https://www.cisa.gov/uscert/sites/default/files/publications/aa22-320a_joint_csa_iranian_government-sponsored_apt_actors_compromise_federal%20network_deploy_crypto%20miner_credential_harvester.pdf
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2022-11-17
modified:
None
Tags:
-'attack.discovery'
-'attack.t1033'
Logsource:
product: windows
category: ps_script
definition: Requirements: Script Block Logging must be enabled
Detection:
selection:
ScriptBlockText|contains|all
:
-'Get-ADComputer '
-' -Filter \*'
ScriptBlockText|contains
:
-' | Select '
-'Out-File'
-'Set-Content'
-'Add-Content'
condition
:
selection
Falsepositives:
-Legitimate admin scripts may use the same technique, it's better to exclude specific computers or users who execute these commands or scripts often
Level:
medium