// MITRE ATT&CK

T1552.006 · Group Policy Preferences

🎯 Credential Access Windows Sub-technique

Sub-technique of T1552 · Unsecured Credentials.

Adversaries may attempt to find unsecured credentials in Group Policy Preferences (GPP). GPP are tools that allow administrators to create domain policies with embedded credentials. These policies allow administrators to set local accounts.(Citation: Microsoft GPP 2016) These group policies are sto...

How to detect & mitigate it

Detecting Group Policy Preferences starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.