Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0072 — Detect Logon Script Modifications and Execution
DET0072

Detect Logon Script Modifications and Execution

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0199 Analytic 0199
Windows

Detects adversary use of logon script configuration via Group Policy or user object attributes, followed by script execution post-authentication. Behavior includes modification of script path or file, then process execution under user logon context.

WinEventLog:Security EventCode=4663, 4670, 4656 WinEventLog:System EventCode=1502, 1503 WinEventLog:Security EventCode=4624, 4648 WinEventLog:Security EventCode=4688
[script_path_keywords] Defenders may tune for known script locations such as NETLOGON, SYSVOL, or \domain\sysvol\*.bat/.ps1
[execution_time_window] May be scoped to user logon hours or first X minutes post-authentication
[user_context] Organizations may focus on specific users/groups with high privilege or remote access

Detected Techniques

1

Details

MITRE ID
DET0072
STIX ID
x-mitre-detection-strategy--3f27e858-2912-4b43-ac03-f668ef30c47e
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.