Startup/Logon Script Added to Group Policy Object
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Detects the modification of Group Policy Objects (GPO) to add a startup/logon script to users or computer objects.
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "Object Changed or Network Share Accessed" AND (((DISPLAYNAME = "gPCMachineExtensionNames,gPCUserExtensionNames" AND SHAREPATH contains "42B5FAAE-6536-11D2-AE5A-0000F87571E3") AND SHAREPATH contains "40B6664F-4972-11D1-A7CA-0000F87571E3,40B66650-4972-11D1-A7CA-0000F87571E3") OR (SHARENAME endswith "\SYSVOL" AND RELATIVETARGETNAME endswith "\scripts.ini,\psscripts.ini" AND ACCESSLIST contains "%%4417")) select Action1.HOSTNAME,Action1.MESSAGE,Action1.USERNAME,Action1.DOMAIN,Action1.TARGETDOMAIN,Action1.TARGETMACHINE,Action1.RELATIVETARGETNAME,Action1.SHARENAME,Action1.SHAREPATH,Action1.OBJECTTYPE,Action1.OBJECTNAME,Action1.CHANGES
Detection
Execution Mode
realtime
Log Sources
Active Directory
Author
Elastic, Josh Nickels, Marius Rothenbücher


