Cross-source coverage

T1484 / ATT&CK

Domain or Tenant Policy Modification

193 rules · 190 families across 8 sources.

1 deprecated hidden · include

From MITRE ATT&CK 19.2

Adversaries may modify the configuration settings of a domain or identity tenant to evade defenses and/or escalate privileges in centrally managed environments. Such services provide a centralized means of managing identity resources such as devices and accounts, and often include configuration settings that may apply between domains or tenants such as trust relationships, identity syncing, or identity federation.

Modifications to domain or tenant settings may include altering domain Group Policy Objects (GPOs) in Microsoft Active Directory (AD) or changing trust settings for domains, including federation trusts relationships between domains or tenants.

With sufficient permissions, adversaries can modify domain or tenant policy settings. Since configuration settings for these services apply to a large number of identity resources, there are a great number of potential attacks malicious outcomes that can stem from this abuse. Examples of such abuse include:

  • modifying GPOs to push a malicious Scheduled Task to computers throughout the domain environment
  • modifying domain trusts to include an adversary-controlled domain, allowing adversaries to forge access tokens that will subsequently be accepted by victim domain resources
  • changing configuration settings within the AD environment to implement a Rogue Domain Controller.
  • adding new, adversary-controlled federated identity providers to identity tenants, allowing adversaries to authenticate as any user managed by the victim tenant

Adversaries may temporarily modify domain or tenant policy, carry out a malicious action(s), and then revert the change to remove suspicious indicators.

Platforms
Windows · Identity Provider
Telemetry
WinEventLog:SecurityWinEventLog:Sysmonm365:unifiedazure:signinlogs

How MITRE says to detect it DET0270

Detection of Domain or Tenant Policy Modifications via AD and Identity Provider

Windows Analytic 0755

Adversary modifies Group Policy Objects (GPOs), domain trust, or directory service objects via GUI, CLI, or programmatic APIs. Behavior includes creation/modification of GPOs, delegation permissions, trust objects, or rogue domain controller registration.

  • WinEventLog:Security EventCode=5136
  • WinEventLog:Security EventCode=4663, 4670, 4656
  • WinEventLog:Sysmon EventCode=1

Identity Provider Analytic 0756

Adversary modifies tenant policy through changes to federation configuration, trust settings, or identity provider additions in Microsoft 365/AzureAD via Portal, PowerShell, or Graph API. Includes setting authentication to federated or updating federated domains.

  • m365:unified Set federation settings on domain|Set domain authentication|Add federated identity provider
  • azure:signinlogs OperationName=SetDomainAuthentication OR Set-FederatedDomain

Sub-techniques with coverage

Counted in the 193 above — a rule tagged a sub-technique covers this technique too.


Wazuh Core Ruleset

115 rules · 113 families
Detection Severity Format
Account Operators Group Changed High Wazuh XML
Administrators Group Changed High Wazuh XML
Allowed Read Only Domain Ccontroller Password Replication Group Changed High Wazuh XML
Backup Operators Group Changed High Wazuh XML
Certificate Service DCOM Access Group Changed High Wazuh XML
Cert Publishers Group Changed High Wazuh XML
Cryptographic Operators Group Changed High Wazuh XML
Denied RODC Password Replication Group Changed High Wazuh XML
Domain Admins Group Changed High Wazuh XML
Domain Controllers Group Changed High Wazuh XML

+ 105 more from Wazuh Core Ruleset → showing the 10 highest-severity

elastic/detection-rules

31 rules
Detection Severity Format
AdminSDHolder SDProp Exclusion Added High Elastic TOML
AWS IAM OIDC Provider Created by Rare User High Elastic TOML
AWS IAM SAML Provider Created High Elastic TOML
Domain Added to Google Workspace Trusted Domains High Elastic TOML
Entra ID Domain Federation Configuration Change High Elastic TOML
Entra ID Federated Identity Credential Issuer Modified High Elastic TOML
Group Policy Abuse for Privilege Addition High Elastic TOML
Application Removed from Blocklist in Google Workspace Medium Elastic TOML
Attempt to Deactivate an Okta Network Zone Medium Elastic TOML
Attempt to Modify an Okta Network Zone Medium Elastic TOML

+ 21 more from elastic/detection-rules → showing the 10 highest-severity

splunk/security_content

24 rules
Detection Severity Format
Active Directory Privilege Escalation Identified Undefined SPL
Azure AD New Custom Domain Added Undefined SPL
Azure AD New Federated Domain Added Undefined SPL
Microsoft Intune DeviceManagementConfigurationPolicies Undefined SPL
O365 Cross-Tenant Access Change Undefined SPL
Windows AD Dangerous Deny ACL Modification Undefined SPL
Windows AD Dangerous Group ACL Modification Undefined SPL
Windows AD Dangerous User ACL Modification Undefined SPL
Windows AD DCShadow Privileges ACL Addition Undefined SPL
Windows AD Domain Replication ACL Addition Undefined SPL

+ 14 more from splunk/security_content → showing the 10 highest-severity

SigmaHQ/sigma

9 rules
Detection Severity Format
Changes to Device Registration Policy High Sigma
Group Policy Abuse for Privilege Addition Medium Sigma
Modify Group Policy Settings Medium Sigma
Modify Group Policy Settings - ScriptBlockLogging Medium Sigma
New Federated Domain Added Medium Sigma
Okta Session Impersonation Granted From Untrusted Domain Medium Sigma
Startup/Logon Script Added to Group Policy Object Medium Sigma
Windows Default Domain GPO Modification Medium Sigma
Windows Default Domain GPO Modification via GPME Medium Sigma

socfortress/Wazuh-Rules

6 rules
Detection Severity Format
operation. · office_365.Operation = Delete group. High Wazuh XML
Sysmon - Event 1: Process creation · Group Policy Reg Change via PowerShell (T1484.001) High Wazuh XML
Sysmon - Event 1: Process creation · Group Policy Reg Change via reg.exe (T1484.001) High Wazuh XML
operation. · office_365.Operation = TeamSettingChanged Low Wazuh XML
operation. · office_365.Operation = Update group. Low Wazuh XML
operation. · office_365.Operation = Update user. Low Wazuh XML

panther-labs/panther-analysis

4 rules
Detection Severity Format
Wiz SAML Identity Provider Change High Panther Python
AppOmni Alert Passthrough Medium Panther Python
ZIA Trust Modification Medium Panther Python
GCP User Added to Privileged Group Low Panther Python

Azure/Azure-Sentinel

3 rules
Detection Severity Format
Federated domain added to Entra ID tenant Undefined KQL
Large Scale Malware Deployment via GPO Scheduled Task Modification Undefined KQL
Policy configuration changes for CloudApp Events Undefined KQL

chronicle/detection-rules

1 rule
Detection Severity Format
entra_id_conditional_access_policy_modification Low YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.