Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0367 — Detect Network Logon Script Abuse via Multi-Event Correlation on Windows
DET0367

Detect Network Logon Script Abuse via Multi-Event Correlation on Windows

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1034 Analytic 1034
Windows

Correlates Group Policy updates that configure network logon scripts with subsequent remote file execution behaviors triggered by user logons to identify potential persistence or execution chains tied to adversarial manipulation of logon scripts.

WinEventLog:Security EventCode=5145 WinEventLog:Security EventCode=4688 WinEventLog:System EventCode=4016, 5312
[TargetObject] Path to network-based script execution; tuning required for environment-specific network shares.
[ParentProcessName] Initial execution process that launches the script; may vary depending on script language or user context.
[TimeWindow] Acceptable time window to correlate Group Policy update with script execution (e.g., 2–10 minutes).
[UserContext] Account initiating execution; useful for filtering known administrative activity.

Detected Techniques

1

Details

MITRE ID
DET0367
STIX ID
x-mitre-detection-strategy--2f20791a-0c97-40c1-a09e-7925321f6f66
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.