Gpscript Execution (1e59c230-6670-45bf-83b0-98903780607e)
Detects the execution of the LOLBIN gpscript, which executes logon or startup scripts configured in Group Policy
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) | Attack Pattern | Gpscript Execution (1e59c230-6670-45bf-83b0-98903780607e) | Sigma-Rules | 1 |