AN0199
Analytic 0199
Windows
Detects adversary use of logon script configuration via Group Policy or user object attributes, followed by script execution post-authentication. Behavior includes modification of script path or file, then process execution under user logon context.
WinEventLog:Security
EventCode=4663, 4670, 4656
WinEventLog:System
EventCode=1502, 1503
WinEventLog:Security
EventCode=4624, 4648
WinEventLog:Security
EventCode=4688
[script_path_keywords]
Defenders may tune for known script locations such as NETLOGON, SYSVOL, or \domain\sysvol\*.bat/.ps1
[execution_time_window]
May be scoped to user logon hours or first X minutes post-authentication
[user_context]
Organizations may focus on specific users/groups with high privilege or remote access