AN0854
Analytic 0854
Windows
Adversary modifies GPO containers or files under SYSVOL using LDAP, ADSI, PowerShell (e.g., New-GPOImmediateTask) or GUI tools. This includes directory object changes (e.g., gPCFileSysPath), delegation assignments (SeEnableDelegationPrivilege), and SYSVOL file writes (ScheduledTasks.xml, GptTmpl.inf).
WinEventLog:Security
EventCode=5136
WinEventLog:Security
EventCode=4663, 4670, 4656
WinEventLog:Security
EventCode=4704
WinEventLog:Sysmon
EventCode=1
WinEventLog:Sysmon
EventCode=11
[ObjectDN]
Focus detection on AD paths like CN=Policies,CN=System,DC=domain,DC=com.
[TargetFilename]
Target specific files like ScheduledTasks.xml or GptTmpl.inf in SYSVOL.
[TimeWindow]
Correlate GPO object change and SYSVOL file modification within N seconds.
[UserContext]
Alert on unexpected modification by non-admins or uncommon accounts.
[CommandLine]
Flag usage of GPO manipulation tools like Set-GPRegistryValue, New-GPOImmediateTask.