Title:
User Discovery And Export Via Get-ADUser Cmdlet
Status:
test
Description:Detects usage of the Get-ADUser cmdlet to collect user information and output it to a file
References:
-http://blog.talosintelligence.com/2022/09/lazarus-three-rats.html
-https://www.microsoft.com/en-us/security/blog/2022/10/18/defenders-beware-a-case-for-post-ransomware-investigations/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-09-09
modified:2022-11-17
Tags:
- -'attack.discovery'
- -'attack.t1033'
Logsource:
- category: process_creation
- product: windows
Detection:
selection_img:
- Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- OriginalFileName:
- 'PowerShell.EXE'
- 'pwsh.dll'
selection_cli:
CommandLine|contains|all:
-'Get-ADUser '
-' -Filter \*'
CommandLine|contains:
-' > '
-' | Select '
-'Out-File'
-'Set-Content'
-'Add-Content'
condition:
all of selection_*
Falsepositives:
-Legitimate admin scripts may use the same technique, it's better to exclude specific computers or users who execute these commands or scripts often
Level:
medium