Group Policy Abuse for Privilege Addition
Description
Detects the first occurrence of a modification to Group Policy Object Attributes to add privileges to user accounts or use them to add users as local admins.
Query · sigma
selection: EventID: 5136 AttributeLDAPDisplayName: gPCMachineExtensionNames AttributeValue|contains: - 827D319E-6EAC-11D2-A4EA-00C04F79F83A - 803E14A0-B4FB-11D0-A0D0-00A0C90F574B condition: selection
Known false positives
- Users allowed to perform these modifications (user found in field SubjectUserName)