LoFP LoFP / t1484.001

t1484.001

TitleTags
general usage of group policy will trigger this detection, also please not gpos modified using tools such as sharpgpoabuse will not generate the ad audit events which enable this detection.
group policy objects are created as part of regular administrative operations, filter as needed.
legitimate execution by system administrators.
legitimate modifications to default domain or default domain controllers gpos
legitimate use
legitimate use of gpme to modify gpos
no false positives have been identified at this time.
the default group policy objects within an ad network may be legitimately updated for administrative operations, filter as needed.
users allowed to perform these modifications (user found in field subjectusername)