Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · defense-impairment, Privilege Escalation

T1484.001 Group Policy Modification

Sub-technique of T1484 Domain or Tenant Policy Modification

Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.