MITRE ATT&CK technique
Domain or Tenant Policy Modification detection rulesT1484
Domain or Tenant Policy Modification (T1484) is a MITRE ATT&CK technique in the Defense Impairment tactic. This page lists the 9 community-maintained Sigma detection rules in the library mapped to T1484 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, azure, m365.
Tactic
Changes to Device Registration Policy
highMonitor and alert for changes to the device registration policy.
azure
Group Policy Abuse for Privilege Addition
mediumDetects the first occurrence of a modification to Group Policy Object Attributes to add privileges to user accounts or use them to add users as local admins.
windows
Modify Group Policy Settings
mediumDetect malicious GPO modifications can be used to implement many other malicious behaviors.
windows · process_creation
Modify Group Policy Settings - ScriptBlockLogging
mediumDetect malicious GPO modifications can be used to implement many other malicious behaviors.
windows · ps_script
New Federated Domain Added
mediumDetects the addition of a new Federated Domain.
m365
Okta Session Impersonation Granted From Untrusted Domain
mediumDetects Okta session impersonation grant event where a user is granted the ability to impersonate another user's session. This event type "user.session.impersonation.grant" signifies that someone has been given temporary access to act on behalf of another user account. Threat actors may abuse this functionality to escalate privileges, access sensitive resources, or perform unauthorized actions while appearing to be the impersonated user. Legitimate use cases are typically limited to Okta support scenarios or authorized administrative troubleshooting.
okta
Startup/Logon Script Added to Group Policy Object
mediumDetects the modification of Group Policy Objects (GPO) to add a startup/logon script to users or computer objects.
windows
Windows Default Domain GPO Modification
mediumDetects modifications to Default Domain or Default Domain Controllers Group Policy Objects (GPOs). Adversaries may modify these default GPOs to deploy malicious configurations across the domain.
windows
Windows Default Domain GPO Modification via GPME
mediumDetects the use of the Group Policy Management Editor (GPME) to modify Default Domain or Default Domain Controllers Group Policy Objects (GPOs). Adversaries may leverage GPME to make stealthy changes in these default GPOs to deploy malicious GPOs configurations across the domain without raising suspicion.
windows · process_creation