---
title: "GetDomainController with PowerShell Script Block"
excerpt: "Remote System Discovery
"
categories:
- Endpoint
last_modified_at: 2022-05-02
toc: true
toc_label: ""
tags:
- Remote System Discovery
- Discovery
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
---
[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
#### Description
The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) to identify the execution of the `Get-DomainController` commandlet. `Get-DomainController` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may use PowerView to enumerate domain computers for situational awareness and Active Directory Discovery.
- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types)
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- **Last Updated**: 2022-05-02
- **Author**: Mauricio Velazco, Splunk
- **ID**: 676b600a-a94d-4951-b346-11329431e6c1
#### Annotations
ATT&CK
#### Search
```
`powershell` EventCode=4104 (ScriptBlockText = "*Get-DomainController*")
| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer UserID EventCode ScriptBlockText
| `security_content_ctime(firstTime)`
| `getdomaincontroller_with_powershell_script_block_filter`
```
#### Macros
The SPL above uses the following Macros:
* [powershell](https://github.com/splunk/security_content/blob/develop/macros/powershell.yml)
* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
> :information_source:
> **getdomaincontroller_with_powershell_script_block_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
#### Required field
* _time
* ScriptBlockText
* Opcode
* Computer
* UserID
* EventCode
#### How To Implement
To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.
#### Known False Positives
Administrators or power users may use this PowerShell commandlet for troubleshooting.
#### Associated Analytic story
* [Active Directory Discovery](/stories/active_directory_discovery)
#### RBA
| Risk Score | Impact | Confidence | Message |
| ----------- | ----------- |--------------|--------------|
| 24.0 | 30 | 80 | Remote system discovery with PowerView on $Computer$ by $UserID$ |
> :information_source:
> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author.
#### Reference
* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/)
* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainController/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainController/)
#### Test Dataset
Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui).
Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server)
* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/getdc.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/getdc.log)
[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getdomaincontroller_with_powershell_script_block.yml) \| *version*: **2**