Group Policy Abuse for Privilege Addition
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Detects the first occurrence of a modification to Group Policy Object Attributes to add privileges to user accounts or use them to add users as local admins.
Severity
Trouble
Rule Requirement
Criteria
Action1:
actionname = "GPO modified" AND DISPLAYNAME = "gPCMachineExtensionNames" AND CHANGES contains "827D319E-6EAC-11D2-A4EA-00C04F79F83A,803E14A0-B4FB-11D0-A0D0-00A0C90F574B"
select Action1.HOSTNAME,Action1.MESSAGE,Action1.DOMAIN,Action1.OPERATION_TYPE,Action1.TARGETDOMAIN,Action1.USERNAME,Action1.CHANGES,Action1.DISPLAYNAME,Action1.OBJECTNAME,Action1.SHAREPATH,Action1.DN,Action1.ACCESSES,Action1.GUID,Action1.SECURITYID
Detection
Execution Mode
realtime
Log Sources
Active Directory
Author
Elastic, Josh Nickels, Marius Rothenbücher


