Elastic medium stable eql
Startup/Logon Script added to Group Policy Object
Detects the modification of Group Policy Objects (GPO) to add a startup/logon script to users or computer objects.
Detection Logic
any where host.os.type == "windows" and event.code in ("5136", "5145") and
(
(
winlog.event_data.AttributeLDAPDisplayName : (
"gPCMachineExtensionNames",
"gPCUserExtensionNames"
) and
winlog.event_data.AttributeValue : "*42B5FAAE-6536-11D2-AE5A-0000F87571E3*" and
winlog.event_data.AttributeValue : (
"*40B66650-4972-11D1-A7CA-0000F87571E3*",
"*40B6664F-4972-11D1-A7CA-0000F87571E3*"
)
) or
(
winlog.event_data.ShareName : "\\\\*\\SYSVOL" and
winlog.event_data.RelativeTargetName : ("*\\scripts.ini", "*\\psscripts.ini") and
winlog.event_data.AccessList:"*%%4417*"
)
) False Positives
- ⚠ Legitimate Administrative Activity
Field Validations
Loading…
Comments (0)
Loading comments...