Startup/Logon Script Added to Group Policy Object

Rule Info

Name
Startup/Logon Script Added to Group Policy Object
Author
Elastic, Josh Nickels, Marius Rothenbücher
Description
Detects the modification of Group Policy Objects (GPO) to add a startup/logon script to users or computer objects.
Date
2024-09-06 00:00:00
Modified
None
Id
123e4e6d-b123-48f8-b261-7214938acaf0
Tags
attack.privilege-escalation attack.t1484.001 attack.t1547 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
Josh
Merge PR #5001 from @joshnck - Add `Startup/Logon Script Added to Group Policy Object`
2024-09-06