Suspicious GPO Discovery With Get-GPO (eb2fd349-ec67-4caa-9143-d79c7fb34441)
Detect use of Get-GPO to get one GPO or all the GPOs in a domain.
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Group Policy Discovery - T1615 (1b20efbf-8063-4fc3-a07d-b575318a301b) | Attack Pattern | Suspicious GPO Discovery With Get-GPO (eb2fd349-ec67-4caa-9143-d79c7fb34441) | Sigma-Rules | 1 |