Computer Discovery And Export Via Get-ADComputer Cmdlet

 Original Source: [Sigma source]
Title: Computer Discovery And Export Via Get-ADComputer Cmdlet
Status: test
Description:Detects usage of the Get-ADComputer cmdlet to collect computer information and output it to a file
References:
  -http://blog.talosintelligence.com/2022/09/lazarus-three-rats.html
  -https://www.microsoft.com/en-us/security/blog/2022/10/18/defenders-beware-a-case-for-post-ransomware-investigations/
  -https://www.cisa.gov/uscert/sites/default/files/publications/aa22-320a_joint_csa_iranian_government-sponsored_apt_actors_compromise_federal%20network_deploy_crypto%20miner_credential_harvester.pdf
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-11-10
modified:2022-11-17
Tags:
  • -'attack.discovery'
  • -'attack.t1033'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    - OriginalFileName:
      - 'PowerShell.EXE'
      - 'pwsh.dll'
  selection_cli:
    CommandLine|contains|all:
      -'Get-ADComputer '
      -' -Filter \*'

    CommandLine|contains:
      -' > '
      -' | Select '
      -'Out-File'
      -'Set-Content'
      -'Add-Content'

  condition:all of selection_*
Falsepositives:
  -Legitimate admin scripts may use the same technique, it's better to exclude specific computers or users who execute these commands or scripts often
Level: medium