Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0305 — Detection of Group Policy Modifications via AD Object Changes and File Activity
DET0305

Detection of Group Policy Modifications via AD Object Changes and File Activity

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0854 Analytic 0854
Windows

Adversary modifies GPO containers or files under SYSVOL using LDAP, ADSI, PowerShell (e.g., New-GPOImmediateTask) or GUI tools. This includes directory object changes (e.g., gPCFileSysPath), delegation assignments (SeEnableDelegationPrivilege), and SYSVOL file writes (ScheduledTasks.xml, GptTmpl.inf).

WinEventLog:Security EventCode=5136 WinEventLog:Security EventCode=4663, 4670, 4656 WinEventLog:Security EventCode=4704 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=11
[ObjectDN] Focus detection on AD paths like CN=Policies,CN=System,DC=domain,DC=com.
[TargetFilename] Target specific files like ScheduledTasks.xml or GptTmpl.inf in SYSVOL.
[TimeWindow] Correlate GPO object change and SYSVOL file modification within N seconds.
[UserContext] Alert on unexpected modification by non-admins or uncommon accounts.
[CommandLine] Flag usage of GPO manipulation tools like Set-GPRegistryValue, New-GPOImmediateTask.

Detected Techniques

1

Details

MITRE ID
DET0305
STIX ID
x-mitre-detection-strategy--7aa7d45f-64da-4f16-a905-b4881da82c62
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.