Suspicious Files in Default GPO Folder
Description
Detects the creation of copy of suspicious files (EXE/DLL) to the default GPO storage folder
Query · sigma
selection:
TargetFilename|contains: \Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\
TargetFilename|endswith:
- .dll
- .exe
condition: selection
Known false positives
- Unknown