Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0055 — Detection strategy for Group Policy Discovery on Windows
DET0055

Detection strategy for Group Policy Discovery on Windows

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0152 Analytic 0152
Windows

Detection of adversary attempts to enumerate Group Policy settings through suspicious command execution (gpresult), PowerShell enumeration (Get-DomainGPO, Get-DomainGPOLocalGroup), and abnormal LDAP queries targeting groupPolicyContainer objects. Defenders observe unusual process lineage, script execution, or LDAP filter activity against domain controllers.

WinEventLog:Security EventCode=4661 WinEventLog:Sysmon EventCode=1 WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106 NSM:Flow query: High-volume LDAP traffic with filters targeting groupPolicyContainer attributes
[TimeWindow] Defines the correlation window to link suspicious PowerShell activity, gpresult execution, and LDAP enumeration.
[UserContext] Identifies accounts expected to perform GPO enumeration (administrators vs. standard users).
[CommandLinePatterns] Patterns for detecting suspicious gpresult or PowerShell cmdlets; tunable to reduce noise in environments where these tools are common.

Detected Techniques

1

Details

MITRE ID
DET0055
STIX ID
x-mitre-detection-strategy--e5eff2eb-4a41-44d1-9c79-4977fb73f569
Analytics
1
Techniques Detected
1
By Tactic
Discovery
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.