Title:Suspicious Get Local Groups Information - PowerShell Status:test Description:Detects the use of PowerShell modules and cmdlets to gather local group information.
Adversaries may use local system permission groups to determine which groups exist and which users belong to a particular group such as the local administrators group.
References: -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.001/T1069.001.md Author: frack113 Date: 2021-12-12 modified:2025-08-22 Tags:
-'attack.discovery'
-'attack.t1069.001'
Logsource:
product: windows
category: ps_script
definition: Requirements: Script Block Logging must be enabled
selection_wmi_class: ScriptBlockText|contains:
'win32_group' condition:selection_localgroup or all of selection_wmi_* Falsepositives:
-Inventory scripts or admin tasks Level:low