Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0381 — Detect Access and Decryption of Group Policy Preference (GPP) Credentials in SYSVOL
DET0381

Detect Access and Decryption of Group Policy Preference (GPP) Credentials in SYSVOL

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1075 Analytic 1075
Windows

Correlates file enumeration of XML files in the SYSVOL share with suspicious process execution that decodes or reads encrypted credentials embedded in Group Policy Preference files (e.g., Get-GPPPassword.ps1, gpprefdecrypt.py, Metasploit). Detects abnormal access to \DOMAIN\SYSVOL combined with XML file parsing or decryption logic.

WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=1 WinEventLog:Security EventCode=5145 WinEventLog:PowerShell Scripts with references to XML parsing, AES decryption, or gpprefdecrypt logic
[UserContext] Tune to exclude authorized admin users or domain controllers accessing SYSVOL
[TimeWindow] Adjust for correlation timing between file access and script execution
[KnownToolsSignature] Extend to include known GPP parsing tool names or script hashes
[HostType] Distinguish between expected access from DCs vs. lateral movement from workstations

Detected Techniques

1

Details

MITRE ID
DET0381
STIX ID
x-mitre-detection-strategy--69b08c7a-c2ab-4e56-935d-ec28143372de
Analytics
1
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.