FORENSIA

ATT&CK · T1484.001 · sub-technique

Group Policy Modification

Tactics: defense-impairment, privilege-escalation

About

Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`. Like other objects in AD, GPOs have access controls associated with them. By default all user accounts in the domain have permission to read GPOs. It is possible to delegate GPO access control permissions, e.g. write access, to specific users or groups in the domain. Malicious GPO modifications can be used to implement many other malicious behaviors such as Scheduled Task/Job, Disable or Modify Tools, Ingress Tool Transfer, Create Account, Service Execution, and more. Since GPOs can control so many user and machine settings in the AD environment, there are a great number of potential attacks that can stem from this GPO abuse. For example, publicly available scripts such as <code>New-GPOImmediateTask</code> can be leveraged to automate the creation of a malicious Scheduled Task/Job by modifying GPO settings, in this case modifying <code>&lt;GPO_PATH&gt;\Machine\Preferences\ScheduledTasks\ScheduledTasks.xml</code>. In some cases an adversary might modify specific user rights like SeEnableDelegationPrivilege, set in <code>&lt;GPO_PATH&gt;\MACHINE\Microsoft\Windows NT\SecEdit\GptTmpl.inf</code>, to achieve a subtle AD backdoor with complete control of the domain because the user account under the adversary's control would then be able to modify GPOs.

Used by actors

5 known groups

Software

8 malware/tools implement this

EmpireEgregorMeteorHermeticWiperPrestigeLockBit 2.0LockBit 3.0Qilin

Corpus indicators tagged with this technique

40 indicators in the corpus carry T1484.001.

IndicatorTypeFamilySevSrc
5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9dfsha256ransomware804
5af1dae21425dda8311a2044209c308525135e1733eeff5dd20649946c6e054csha256ransomware802
cb747c0134f99d5033bac6e966864e2435a2a94244ca8e3f614f4992df93ff10sha256ransomware802
9ddae47ff968343a8c32a5344060257fdc08e2a7bdb9a227c8b3a584ee3c9f1esha256ransomware802
5abe477517f51d81061d2e69a9adebdcda80d36667d0afabe103fda4802d33dbsha256ransomware802
f8965fdce668692c3785afa3559159f9a18287bc0d53abb21902895a8ecf221bsha256ransomware802
e7cc7b32d844ec6a2f41f0efbc64a0783afb56e4sha1ransomware782
6afc6b04cf73dd461e4a4956365f25c1f1162387sha1ransomware782
1fa071303fb846308571e64727501fb98b1c2be6sha1ransomware782
96f0dbf52aed0afd43e44500116b04b674f7358esha1ransomware782
7556ae58c215b8245a43f764f0676c7a8f0fdd1asha1ransomware782
ab5ad04bb822435e5453706cd86cc001ee555aeesha1ransomware782
68fec379f2ae76c3d2ce913f7be650cea1d06990sha1ransomware784
adac9984b3cc43d66a0d33079bbec299md5ransomware76110
ae0e536766788478263bf448a9381641md5ransomware76110
3c471ebc947cdf32240a90ffadf49b13md5ransomware76110
4be8bb62f0ebbcf4ce52c35ab6f794f5md5ransomware76110
b3e418d30312c1b2c58a791286868f42md5ransomware76110
c2764744dcb4b0e1db79ca1e8bf65368md5ransomware76106
d2f72897e8986303d5567eb2384932b8md5ransomware76106
de1522f9219497632f30f8a6e72f26b6md5ransomware76106
fdae2beb813778b4540a997706862096md5ransomware76106
d12a5b36dd00586cc374a1cae43efed4md5ransomware76106
846dc77c1246db20d976346e0e359502md5ransomware76110
02944c8a5535cdb5b2cbb893db2d5acfmd5ransomware76110
5761bd63da03686fc480245da7bd1e9fmd5ransomware764
53c616677bc7e2a0a03127f19166d007md5ransomware76110
b6b51508ad6f462c45fe102c85d246c8md5ransomware762
8f0577d28c4ff5f71b149f444bfaba8emd5ransomware762
eef8a950952696b018aa9c6da2f5d7admd5ransomware762

Showing the top 30 by severity of 40.