Suspicious Files in Default GPO Folder

 Original Source: [Sigma source]
Title: Suspicious Files in Default GPO Folder
Status: test
Description:Detects the creation of copy of suspicious files (EXE/DLL) to the default GPO storage folder
References:
  -https://redcanary.com/blog/intelligence-insights-november-2021/
Author: elhoim
Date: 2022-04-28
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1036.005'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    TargetFilename|contains: '\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\'
    TargetFilename|endswith:
      -'.dll'
      -'.exe'

  condition:selection
Falsepositives:
  -Unknown
Level: medium