Group Policy Abuse for Privilege Addition

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects the first occurrence of a modification to Group Policy Object Attributes to add privileges to user accounts or use them to add users as local admins.

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "GPO modified" AND DISPLAYNAME = "gPCMachineExtensionNames" AND CHANGES contains "827D319E-6EAC-11D2-A4EA-00C04F79F83A,803E14A0-B4FB-11D0-A0D0-00A0C90F574B" select Action1.HOSTNAME,Action1.MESSAGE,Action1.DOMAIN,Action1.OPERATION_TYPE,Action1.TARGETDOMAIN,Action1.USERNAME,Action1.CHANGES,Action1.DISPLAYNAME,Action1.OBJECTNAME,Action1.SHAREPATH

Detection

Execution Mode

realtime

Log Sources

Active Directory

Author

Elastic, Josh Nickels, Marius Rothenbücher