
Rule Info
Name
User Discovery And Export Via Get-ADUser Cmdlet - PowerShell
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects usage of the Get-ADUser cmdlet to collect user information and output it to a file
Date
2022-11-17 00:00:00
Modified
None
Id
c2993223-6da8-4b1a-88ee-668b8bf315e9
Tags
attack.discovery attack.t1033 DEMO
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit
nasreddine.bencherchali@nextron-systems.com
Update proc_creation_win_user_discovery_get_aduser.yml
2022-09-09