Skip to content

Hide Navigation Hide TOC

AD Groups Or Users Enumeration Using PowerShell - ScriptBlock (88f0884b-331d-403d-a3a1-b668cf035603)

Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.

Cluster A Galaxy A Cluster B Galaxy B Level
Local Groups - T1069.001 (a01bf75f-00b2-4568-a58f-565ff9bf202b) Attack Pattern AD Groups Or Users Enumeration Using PowerShell - ScriptBlock (88f0884b-331d-403d-a3a1-b668cf035603) Sigma-Rules 1
Local Groups - T1069.001 (a01bf75f-00b2-4568-a58f-565ff9bf202b) Attack Pattern Permission Groups Discovery - T1069 (15dbf668-795c-41e6-8219-f0447c0e64ce) Attack Pattern 2