Active Directory Enumeration via PowerShell or Net Commands

This rule detects potential Active Directory enumeration attempts by monitoring for the execution of common command-line tools and PowerShell cmdlets used to query domain information, such as users, groups, and domain controllers.