{"id":"T1484.001","name":"Group Policy Modification","url":"https://attack.mitre.org/techniques/T1484/001","tactics":["defense-impairment","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0305","stix_id":"x-mitre-detection-strategy--7aa7d45f-64da-4f16-a905-b4881da82c62","name":"Detection of Group Policy Modifications via AD Object Changes and File Activity","url":"https://attack.mitre.org/detectionstrategies/DET0305","analytics":[{"id":"AN0854","stix_id":"x-mitre-analytic--ec6e1f3c-e9ff-4944-a426-863eaf9979ea","name":"Analytic 0854","description":"Adversary modifies GPO containers or files under SYSVOL using LDAP, ADSI, PowerShell (e.g., New-GPOImmediateTask) or GUI tools. This includes directory object changes (e.g., gPCFileSysPath), delegation assignments (SeEnableDelegationPrivilege), and SYSVOL file writes (ScheduledTasks.xml, GptTmpl.inf).","url":"https://attack.mitre.org/detectionstrategies/DET0305#AN0854","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=5136","data_component":"DC0066","data_component_name":"Active Directory Object Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4704","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ObjectDN","description":"Focus detection on AD paths like CN=Policies,CN=System,DC=domain,DC=com."},{"field":"TargetFilename","description":"Target specific files like ScheduledTasks.xml or GptTmpl.inf in SYSVOL."},{"field":"TimeWindow","description":"Correlate GPO object change and SYSVOL file modification within N seconds."},{"field":"UserContext","description":"Alert on unexpected modification by non-admins or uncommon accounts."},{"field":"CommandLine","description":"Flag usage of GPO manipulation tools like Set-GPRegistryValue, New-GPOImmediateTask."}],"live":true,"detection_strategies":["DET0305"],"techniques":["T1484.001"]}],"live":true,"version":"1.0","techniques":["T1484.001"]}],"sigma_rules":[{"id":"123e4e6d-b123-48f8-b261-7214938acaf0","title":"Startup/Logon Script Added to Group Policy Object","author":"Elastic, Josh Nickels, Marius Rothenbücher","status":"test","level":"medium","date":"2024-09-06","modified":null,"description":"Detects the modification of Group Policy Objects (GPO) to add a startup/logon script to users or computer objects.\n","references":["https://www.elastic.co/guide/en/security/current/startup-logon-script-added-to-group-policy-object.html"],"logsource":{"product":"windows","service":"security"},"tags":["attack.persistence","attack.privilege-escalation","attack.defense-impairment","attack.t1484.001","attack.t1547"],"path":"rules/windows/builtin/security/win_security_susp_group_policy_startup_script_added_to_gpo.yml","techniques":["T1484.001","T1547"],"cves":[]},{"id":"1c480e10-7ee1-46d4-8ed2-85f9789e3ce4","title":"Group Policy Abuse for Privilege Addition","author":"Elastic, Josh Nickels, Marius Rothenbücher","status":"test","level":"medium","date":"2024-09-04","modified":null,"description":"Detects the first occurrence of a modification to Group Policy Object Attributes to add privileges to user accounts or use them to add users as local admins.\n","references":["https://www.elastic.co/guide/en/security/current/group-policy-abuse-for-privilege-addition.html#_setup_275"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.defense-impairment","attack.t1484.001"],"path":"rules/windows/builtin/security/win_security_susp_group_policy_abuse_privilege_addition.yml","techniques":["T1484.001"],"cves":[]},{"id":"ada4b0c4-758b-46ac-9033-9004613a150d","title":"Modify Group Policy Settings","author":"frack113","status":"test","level":"medium","date":"2022-08-19","modified":null,"description":"Detect malicious GPO modifications can be used to implement many other malicious behaviors.","references":["https://github.com/redcanaryco/atomic-red-team/blob/40b77d63808dd4f4eafb83949805636735a1fd15/atomics/T1484.001/T1484.001.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.defense-impairment","attack.t1484.001"],"path":"rules/windows/process_creation/proc_creation_win_reg_modify_group_policy_settings.yml","techniques":["T1484.001"],"cves":[]},{"id":"b7216a7d-687e-4c8d-82b1-3080b2ad961f","title":"Modify Group Policy Settings - ScriptBlockLogging","author":"frack113","status":"test","level":"medium","date":"2022-08-19","modified":null,"description":"Detect malicious GPO modifications can be used to implement many other malicious behaviors.","references":["https://github.com/redcanaryco/atomic-red-team/blob/40b77d63808dd4f4eafb83949805636735a1fd15/atomics/T1484.001/T1484.001.md"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.privilege-escalation","attack.defense-impairment","attack.t1484.001"],"path":"rules/windows/powershell/powershell_script/posh_ps_modify_group_policy_settings.yml","techniques":["T1484.001"],"cves":[]},{"id":"dcff7e85-d01f-4eb5-badd-84e2e6be8294","title":"Windows Default Domain GPO Modification via GPME","author":"TropChaud","status":"experimental","level":"medium","date":"2025-11-22","modified":null,"description":"Detects the use of the Group Policy Management Editor (GPME) to modify Default Domain or Default Domain Controllers Group Policy Objects (GPOs).\nAdversaries may leverage GPME to make stealthy changes in these default GPOs to deploy malicious GPOs configurations across the domain without raising suspicion.\n","references":["https://www.trendmicro.com/en_us/research/25/i/unmasking-the-gentlemen-ransomware.html","https://adsecurity.org/?p=3377","https://sdmsoftware.com/general-stuff/launching-the-new-gp-management-editor-from-the-command-line/","https://www.pentestpartners.com/security-blog/living-off-the-land-gpo-style/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.defense-impairment","attack.t1484.001"],"path":"rules/windows/process_creation/proc_creation_win_mmc_default_domain_gpo_modification_via_gpme.yml","techniques":["T1484.001"],"cves":[]},{"id":"e5ac86dd-2da1-454b-be74-05d26c769d7d","title":"Windows Default Domain GPO Modification","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-11-22","modified":null,"description":"Detects modifications to Default Domain or Default Domain Controllers Group Policy Objects (GPOs).\nAdversaries may modify these default GPOs to deploy malicious configurations across the domain.\n","references":["https://www.trendmicro.com/en_us/research/25/i/unmasking-the-gentlemen-ransomware.html","https://adsecurity.org/?p=3377","https://www.pentestpartners.com/security-blog/living-off-the-land-gpo-style/","https://jgspiers.com/audit-group-policy-changes/"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.defense-impairment","attack.t1484.001"],"path":"rules/windows/builtin/security/win_security_default_domain_gpo_modification.yml","techniques":["T1484.001"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2023-26360","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}