AADInternals PowerShell Cmdlets Execution - ProccessCreation
Description
Detects ADDInternals Cmdlet execution. A tool for administering Azure AD and Office 365. Which can be abused by threat actors to attack Azure AD or Office 365.
Query · sigma
selection_img: - Image|endswith: - \powershell.exe - \powershell_ise.exe - \pwsh.exe - OriginalFileName: - PowerShell.Exe - pwsh.dll selection_cli: CommandLine|contains: - Add-AADInt - ConvertTo-AADInt - Disable-AADInt - Enable-AADInt - Export-AADInt - Find-AADInt - Get-AADInt - Grant-AADInt - Initialize-AADInt - Install-AADInt - Invoke-AADInt - Join-AADInt - New-AADInt - Open-AADInt - Read-AADInt - Register-AADInt - Remove-AADInt - Reset-AADInt - Resolve-AADInt - Restore-AADInt - Save-AADInt - Search-AADInt - Send-AADInt - Set-AADInt - Start-AADInt - Unprotect-AADInt - Update-AADInt condition: all of selection_*
Known false positives
- Legitimate use of the library for administrative activity