// MITRE ATT&CK

T1484.001 · Group Policy Modification

🎯 Defense Impairment Windows Sub-technique

Sub-technique of T1484 · Domain or Tenant Policy Modification.

Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are co...

How to detect & mitigate it

Detecting Group Policy Modification starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.