Startup/Logon Script Added to Group Policy Object

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects the modification of Group Policy Objects (GPO) to add a startup/logon script to users or computer objects.

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "Object Changed or Network Share Accessed" AND (((DISPLAYNAME = "gPCMachineExtensionNames,gPCUserExtensionNames" AND SHAREPATH contains "42B5FAAE-6536-11D2-AE5A-0000F87571E3") AND SHAREPATH contains "40B6664F-4972-11D1-A7CA-0000F87571E3,40B66650-4972-11D1-A7CA-0000F87571E3") OR (SHARENAME endswith "\SYSVOL" AND RELATIVETARGETNAME endswith "\scripts.ini,\psscripts.ini" AND ACCESSLIST contains "%%4417")) select Action1.HOSTNAME,Action1.MESSAGE,Action1.USERNAME,Action1.DOMAIN,Action1.TARGETDOMAIN,Action1.TARGETMACHINE,Action1.RELATIVETARGETNAME,Action1.SHARENAME,Action1.SHAREPATH,Action1.OBJECTTYPE,Action1.OBJECTNAME,Action1.CHANGES

Detection

Execution Mode

realtime

Log Sources

Active Directory

Author

Elastic, Josh Nickels, Marius Rothenbücher