Group Policy Abuse for Privilege Addition
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Detects the first occurrence of a modification to Group Policy Object Attributes to add privileges to user accounts or use them to add users as local admins.
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "GPO modified" AND DISPLAYNAME = "gPCMachineExtensionNames" AND CHANGES contains "827D319E-6EAC-11D2-A4EA-00C04F79F83A,803E14A0-B4FB-11D0-A0D0-00A0C90F574B" select Action1.HOSTNAME,Action1.MESSAGE,Action1.DOMAIN,Action1.OPERATION_TYPE,Action1.TARGETDOMAIN,Action1.USERNAME,Action1.CHANGES,Action1.DISPLAYNAME,Action1.OBJECTNAME,Action1.SHAREPATH
Detection
Execution Mode
realtime
Log Sources
Active Directory
Author
Elastic, Josh Nickels, Marius Rothenbücher


