AN0152
Analytic 0152
Windows
Detection of adversary attempts to enumerate Group Policy settings through suspicious command execution (gpresult), PowerShell enumeration (Get-DomainGPO, Get-DomainGPOLocalGroup), and abnormal LDAP queries targeting groupPolicyContainer objects. Defenders observe unusual process lineage, script execution, or LDAP filter activity against domain controllers.
WinEventLog:Security
EventCode=4661
WinEventLog:Sysmon
EventCode=1
WinEventLog:PowerShell
EventCode=4103, 4104, 4105, 4106
NSM:Flow
query: High-volume LDAP traffic with filters targeting groupPolicyContainer attributes
[TimeWindow]
Defines the correlation window to link suspicious PowerShell activity, gpresult execution, and LDAP enumeration.
[UserContext]
Identifies accounts expected to perform GPO enumeration (administrators vs. standard users).
[CommandLinePatterns]
Patterns for detecting suspicious gpresult or PowerShell cmdlets; tunable to reduce noise in environments where these tools are common.